PT-2026-45365 · Apache · Apache Airflow

·

CVE-2026-40963

·

Published

2026-06-01

·

Updated

2026-07-13

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions apache-airflow versions prior to 3.2.2
Description The 'structure data' endpoint in the Airflow UI fails to verify if the caller has read permissions for linked DAGs (Directed Acyclic Graphs, which are collections of all the tasks you want to run, organized in a way that reflects their relationships and dependencies). Consequently, an authenticated UI or API user with authorization for one DAG can enumerate linked DAG IDs and dependency metadata for other DAGs they are not authorized to access. This issue impacts deployments using per-DAG read scoping to maintain the privacy of DAG dependency topology across different teams.
Recommendations Upgrade to version 3.2.2 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-40963
CVE-2026-40963
ECHO-583E-AD50-6EE4
GHSA-GPRJ-XVQ8-W53Q
PYSEC-2026-2349

Affected Products

Apache Airflow