Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to.

Users are advised to upgrade to 3.1.7 or later, which resolves this issue
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 09 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
Description Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
Title Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors
Weaknesses CWE-200
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-02-09T17:18:52.980Z

Reserved: 2026-01-21T15:52:53.472Z

Link: CVE-2026-24098

cve-icon Vulnrichment

Updated: 2026-02-09T15:29:08.671Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-09T11:16:14.660

Modified: 2026-02-09T16:16:00.963

Link: CVE-2026-24098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses