CVE-2026-22922

Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

11 Feb 2026, 18:30

Type Values Removed Values Added
References () https://github.com/apache/airflow/pull/60412 - () https://github.com/apache/airflow/pull/60412 - Issue Tracking, Patch
References () https://lists.apache.org/thread/gdb7vffhpmrj5hp1j0oj1j13o4vmsq40 - () https://lists.apache.org/thread/gdb7vffhpmrj5hp1j0oj1j13o4vmsq40 - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/02/09/2 - () http://www.openwall.com/lists/oss-security/2026/02/09/2 - Mailing List, Third Party Advisory
First Time Apache airflow
Apache
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

09 Feb 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/02/09/2 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

09 Feb 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 11:16

Updated : 2026-02-11 18:30


NVD link : CVE-2026-22922

Mitre link : CVE-2026-22922

CVE.ORG link : CVE-2026-22922


JSON object : View

Products Affected

apache

  • airflow
CWE
CWE-648

Incorrect Use of Privileged APIs