PT-2026-25891 · Apache · Apache Airflow

·

CVE-2026-26929

·

Published

2026-03-17

·

Updated

2026-03-18

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.0.0 through 3.1.7
Description The FastAPI DagVersion listing API in Apache Airflow does not enforce per-DAG authorization filtering when a request is made with the dag id parameter set to '~' (wildcard for all DAGs). This allows the retrieval of version metadata for DAGs that the requesting user is not authorized to access.
Recommendations Upgrade to Apache Airflow version 3.1.8 or later.

Exploit

Fix

DoS

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05612
BIT-AIRFLOW-2026-26929
CVE-2026-26929
ECHO-5261-4F07-492A
GHSA-4M3H-WP5W-5HQH
PYSEC-2026-14

Affected Products

Apache Airflow