CVE-2026-24098

Severity
6.5MEDIUM
EPSS
0.0%
top 93.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9

Description

Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDapache/airflow3.0.03.1.7
PyPIapache-airflow< 3.1.7

Patches

🔴Vulnerability Details

3
CVEList
Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors2026-02-09
OSV
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users2026-02-09
GHSA
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users2026-02-09

🕵️Threat Intelligence

1
Wiz
CVE-2026-24098 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-24098 (MEDIUM CVSS 6.5) | Apache Airflow versions 3.0.0 - 3.1 | cvebase.io