PT-2026-33594 · Airflow · Airflow

·

CVE-2026-32228

·

Published

2026-04-18

·

Updated

2026-07-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Airflow versions prior to 3.2.0
Description A user with asset materialize permission via the UI or API can trigger DAGs (Directed Acyclic Graphs, which are collections of all the tasks you want to run, organized in a way that reflects their relationships) to which they do not have access.
Recommendations Update to version 3.2.0.

Exploit

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-32228
CVE-2026-32228
ECHO-6678-A89A-3AEC
GHSA-H97W-PM3W-MWMC
PYSEC-2026-2360

Affected Products

Airflow