← back
CVE-2026-24098

Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors

CVSS 6.5 MEDIUMEPSS 0.7%CWE-200
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
09 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →