Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access.
Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
References
| Link | Resource |
|---|---|
| https://github.com/apache/airflow/pull/60412 | Issue Tracking Patch |
| https://lists.apache.org/thread/gdb7vffhpmrj5hp1j0oj1j13o4vmsq40 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/02/09/2 | Mailing List Third Party Advisory |
Configurations
History
11 Feb 2026, 18:30
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/apache/airflow/pull/60412 - Issue Tracking, Patch | |
| References | () https://lists.apache.org/thread/gdb7vffhpmrj5hp1j0oj1j13o4vmsq40 - Mailing List, Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/02/09/2 - Mailing List, Third Party Advisory | |
| First Time |
Apache airflow
Apache |
|
| CPE | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
09 Feb 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Feb 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 11:16
Updated : 2026-02-11 18:30
NVD link : CVE-2026-22922
Mitre link : CVE-2026-22922
CVE.ORG link : CVE-2026-22922
JSON object : View
Products Affected
apache
- airflow
CWE
CWE-648
Incorrect Use of Privileged APIs
