Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
History

Wed, 11 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

Tue, 10 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Vendors & Products Apache
Apache airflow

Mon, 09 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
References

Mon, 09 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
Description Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
Title Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2026-02-09T10:32:53.910Z

Updated: 2026-02-09T17:18:52.980Z

Reserved: 2026-01-21T15:52:53.472Z

Link: CVE-2026-24098

cve-icon Vulnrichment

Updated: 2026-02-09T17:18:52.980Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-09T11:16:14.660

Modified: 2026-02-11T18:30:27.193

Link: CVE-2026-24098

cve-icon Redhat

No data.