Improper access control in Apache Airflow - CVE-2026-40690
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the asset dependency graph view when handling asset graph browsing requests. A remote user can browse the graph for unauthorized assets to disclose the existence and names of DAGs and assets outside their authorized scope.
Exploitation requires read access to at least one DAG.