PT-2026-34877 · Apache+3 · Apache Airflow+1

Jarek Potiuk

+1

·

Published

2026-04-24

·

Updated

2026-04-28

·

CVE-2026-40690

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined versions prior to 3.2.1
Description The asset dependency graph fails to restrict nodes based on the viewer's DAG read permissions. This allows a user with read access to at least one DAG to browse the asset graph for any other asset in the deployment, enabling them to discover the existence and names of DAGs and assets outside their authorized scope.
Recommendations Upgrade to version 3.2.1.

Fix

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-40690
CVE-2026-40690
GHSA-W7RC-Q6CM-F5GM

Affected Products

Apache Airflow
Airflow