The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.
References
| Link | Resource |
|---|---|
| https://github.com/apache/airflow/pull/65344 | Issue Tracking Patch |
| https://lists.apache.org/thread/12nbzwwby7g883w2j13gn7ny1545xob9 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/05/31/4 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-01 09:16
Updated : 2026-07-21 19:10
NVD link : CVE-2026-41014
Mitre link : CVE-2026-41014
CVE.ORG link : CVE-2026-41014
JSON object : View
Products Affected
apache
- airflow
CWE
CWE-862
Missing Authorization
