PT-2026-25892 · Apache · Apache Airflow

Shubham Raj

·

Published

2026-03-17

·

Updated

2026-03-17

·

CVE-2026-28563

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view.
Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2026-28563

Affected Products

Apache Airflow