Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
History

Wed, 11 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

Tue, 10 Feb 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Vendors & Products Apache
Apache airflow

Mon, 09 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
References

Mon, 09 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
Description Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
Title Apache Airflow: Airflow externalLogUrl Permission Bypass
Weaknesses CWE-648
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2026-02-09T10:33:49.649Z

Updated: 2026-02-09T17:18:51.694Z

Reserved: 2026-01-13T14:15:57.516Z

Link: CVE-2026-22922

cve-icon Vulnrichment

Updated: 2026-02-09T17:18:51.694Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-09T11:16:13.187

Modified: 2026-02-11T18:30:44.510

Link: CVE-2026-22922

cve-icon Redhat

No data.