Missing Authorization in Apache Airflow - CVE-2026-75158
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose asset events belonging to unauthorized Dags.
The vulnerability exists due to missing authorization in the /assets/events API when handling asset event requests. A remote user can send requests to disclose asset events for Dags they are not authorized to read.
The count query and pagination metadata can reveal the existence of hidden Dags.