CVE-2026-32228

HIGH

Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to

Title source: cna
STIX 2.1

Description

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 33.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
apache/airflow 3.0.0 - 3.2.0
Apache Software Foundation/Apache Airflow 3.0.0 - 3.2.0
pypi/apache-airflow-core 3.0.0 - 3.2.0PyPI
Published Apr 18, 2026
Tracked Since Apr 18, 2026