CVE-2026-32228

HIGH

Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to

Title source: cna

Description

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-863
Status published
Products (3)
apache/airflow 3.0.0 - 3.2.0
Apache Software Foundation/Apache Airflow 3.0.0 - 3.2.0
pypi/apache-airflow-core 3.0.0 - 3.2.0PyPI
Published Apr 18, 2026
Tracked Since Apr 18, 2026