Incorrect authorization in Apache Airflow - CVE-2026-49296
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the GET /api/v2/dagSources/{dag_id} endpoint and equivalent dag-source view when returning source files for dag source requests. A remote user can request the source for an authorized dag id to disclose sensitive information.
Only deployments that co-locate multiple dags in a single source file and rely on per-dag access control for source visibility are affected; single-dag-per-file deployments are not.