CVE-2026-41014
published 2026-06-01CVE-2026-41014: The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.35%
27.4th percentile
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | >= 3.2.0 < 3.2.2 | 3.2.2 |
| apache_software_foundation | apache_airflow | >= 3.2.0 < 3.2.2 | 3.2.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization.
ghsa_unreviewed·2026-06-01
CVE-2026-41014 [MEDIUM] CWE-862 The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization.
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.
GHSA
Apache Airflow has a Missing Authorization issue
ghsa·2026-06-01
CVE-2026-41014 [MEDIUM] CWE-862 Apache Airflow has a Missing Authorization issue
Apache Airflow has a Missing Authorization issue
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.
VulDB
Apache Airflow up to 3.2.1 partitioned_dag_runs Endpoint /ui/partitioned_dag_runs access control
vuldb·2026-05-31
CVE-2026-41014 [CRITICAL] Apache Airflow up to 3.2.1 partitioned_dag_runs Endpoint /ui/partitioned_dag_runs access control
A vulnerability classified as critical was found in Apache Airflow up to 3.2.1. This affects an unknown part of the file /ui/partitioned_dag_runs of the component partitioned_dag_runs Endpoint. Such manipulation leads to improper access controls.
This vulnerability is documented as CVE-2026-41014. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-01
Published