PT-2026-7102 · Apache · Apache Airflow
34Selen
+1
·
Published
2026-02-09
·
Updated
2026-02-12
·
CVE-2026-22922
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions 3.1.0 through 3.1.6
Description
An authorization flaw exists in Apache Airflow that could allow an authenticated user with limited task permissions to view task logs without proper authorization. The issue affects systems where users have custom permissions restricting access to task logs, but still permit task access.
Recommendations
Upgrade to Apache Airflow version 3.1.7 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow