CVE-2026-41014 Details
Description
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.
A vulnerability exists in the Apache Airflow UI in versions 3.2.0 prior to 3.2.2, specifically within the partitioned_dag_runs endpoints. This issue arises because the endpoints only enforce asset-level access control, lacking per-DAG authorization. As a result, an authenticated user with global Asset:read permission could access and enumerate partition run states, schedule configurations, and asset wiring for DAGs that they were not authorized to read. This vulnerability impacts deployments that depend on per-DAG read permissions while allowing users broader Asset access.
Users are advised to upgrade to Apache Airflow version 3.2.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/31/4 | CVE | Mailing ListThird Party Advisory |
| https://github.com/apache/airflow/pull/65344 | [email protected] | Issue TrackingPatch |
| https://lists.apache.org/thread/12nbzwwby7g883w2j13gn7ny1545xob9 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache airflow | >= 3.2.0, < 3.2.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | CVE Modified | CVE |
| Jun 1, 2026 | New CVE Received | [email protected] |