PT-2026-33594 · Apache · Apache Airflow

Ahmad Abuzaid

+1

·

Published

2026-04-18

·

Updated

2026-04-18

·

CVE-2026-32228

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32228

Affected Products

Apache Airflow