PT-2026-96119 · Apache · Apache Airflow

·

CVE-2026-75158

·

Published

2026-09-21

·

Updated

2026-09-26

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.3.2
Description The /assets/events API endpoint fails to restrict asset events to the Dags that the caller is authorized to read. Authenticated users with asset-read access can enumerate asset events for Dags they lack permission to view, exposing the source Dag ID, task ID, run ID, and event timestamps. Additionally, the absence of a filter in the count query allows the total entries and pagination features to disclose the existence of hidden Dags. This issue occurs in deployments utilizing per-Dag access control to separate teams or tenants.
Recommendations Upgrade to apache-airflow version 3.3.2 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-75158
CVE-2026-75158
PYSEC-2026-3988

Affected Products

Apache Airflow