Access Control Flaw in Apache Airflow API Allows Unauthorized Event Enumeration
CVE-2026-75158

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 September 2026

What is CVE-2026-75158?

The Apache Airflow API's '/assets/events' endpoint allows authenticated users with asset-read access to retrieve asset events associated with Dags they are not authorized to access. This flaw permits users to enumerate sensitive information, including DAG IDs and timestamps, which can expose the architecture and flow of workflows within the deployment. The lack of proper filters also leads to unintended disclosure of total entries and pagination details, empowering attackers to identify hidden Dags while circumventing access restrictions. Users are advised to upgrade to Apache Airflow version 3.3.2 or higher to mitigate this issue.

Affected Version(s)

Apache Airflow 0 < 3.3.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
Jarek Potiuk
.