Improper access control in Apache Airflow - CVE-2026-41014
Published: June 4, 2026
Apache Airflow
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in /ui/partitioned_dag_runs endpoints when handling UI or API requests. A remote user can query the endpoints to disclose sensitive information.
The issue affects deployments that rely on per-Dag read scoping while granting users broader Asset:read access.