CVE-2026-41014 PUBLISHED

Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints

Assigner: apache
Reserved: 16.04.2026 Published: 01.06.2026 Updated: 01.06.2026

The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to apache-airflow 3.2.2 or later.

Product Status

Vendor Apache Software Foundation
Product Apache Airflow
Versions Default: unaffected
  • affected from 3.2.0 to 3.2.2 (excl.)

Credits

  • Yalguun Tumenkhuu (fg0x0) finder
  • Jarek Potiuk remediation developer

References

Problem Types

  • CWE-862: Missing Authorization CWE