CVE-2026-28563
Apache Airflow: DAG authorization bypass
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.
| CWE | CWE-732 |
| Vendor | apache software foundation |
| Product | apache airflow |
| Published | Mar 17, 2026 |
| Last Updated | Mar 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache airflow
Be the first to know when new medium vulnerabilities affecting apache software foundation apache airflow are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Airflow
3.0.0 < 3.1.8
References
Credits
Masamune - Unit515 OPSWAT Shubham Raj