PT-2026-7103 · Apache · Apache Airflow
Saurabh
·
Published
2026-02-09
·
Updated
2026-03-11
·
CVE-2026-24098
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 3.1.7
Description
Authenticated users of the Airflow user interface, with permissions to specific Dags, could view import errors generated by other Dags they were not authorized to access.
Recommendations
Upgrade to version 3.1.7 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow