Improper access control in Apache Airflow - CVE-2026-38743

 

Improper access control in Apache Airflow - CVE-2026-38743

Published: August 25, 2026


Vulnerability identifier: #VU145332
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-38743
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /ui/dags endpoint when handling authenticated requests that embed Human-in-the-Loop and TaskInstance records. A remote user can retrieve DAG-related records outside their authorized scope to disclose sensitive information.

The exposed data may include HITL prompts with request parameters and full TaskInstance details.


Affected software

Apache Airflow

How to mitigate CVE-2026-38743

Install security update from vendor's website.

Apache Airflow - update to 3.2.1

External References

Related Security Bulletins