CVE-2026-28563

MEDIUM

Apache Airflow: DAG authorization bypass

Title source: cna
STIX 2.1

Description

Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

Scores

CVSS v3 4.3
EPSS 0.0006
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (3)
apache/airflow 3.0.0 - 3.1.8
Apache Software Foundation/Apache Airflow 3.0.0 - 3.1.8
pypi/apache-airflow 3.0.0 - 3.1.8PyPI
Published Mar 17, 2026
Tracked Since Mar 17, 2026