CVE-2026-24098 PUBLISHED

Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors

Assigner: apache
Reserved: 21.01.2026 Published: 09.02.2026 Updated: 09.02.2026

Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to.

Users are advised to upgrade to 3.1.7 or later, which resolves this issue

Product Status

Vendor Apache Software Foundation
Product Apache Airflow
Versions Default: unaffected
  • affected from 0 to 3.1.7 (excl.)

Credits

  • Saurabh finder

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE