Improper access control in Apache Airflow - CVE-2026-40690

 

Improper access control in Apache Airflow - CVE-2026-40690

Published: August 25, 2026


Vulnerability identifier: #VU145333
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40690
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the asset dependency graph view when handling asset graph browsing requests. A remote user can browse the graph for unauthorized assets to disclose the existence and names of DAGs and assets outside their authorized scope.

Exploitation requires read access to at least one DAG.


Affected software

Apache Airflow

How to mitigate CVE-2026-40690

Install security update from vendor's website.

Apache Airflow - update to 3.2.1

External References

Related Security Bulletins