CVE-2026-32228
HIGHApache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
Title source: cnaDescription
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.
Scores
CVSS v3
7.5
EPSS
0.0007
EPSS Percentile
22.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-863
Status
published
Products (3)
apache/airflow
3.0.0 - 3.2.0
Apache Software Foundation/Apache Airflow
3.0.0 - 3.2.0
pypi/apache-airflow-core
3.0.0 - 3.2.0PyPI
Published
Apr 18, 2026
Tracked Since
Apr 18, 2026