CVE-2026-22922

Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
Summary
  • (es) Las versiones 3.1.0 a 3.1.6 de Apache Airflow contienen una falla de autorización que puede permitir a un usuario autenticado con permisos personalizados limitados al acceso a tareas ver los registros de tareas sin tener acceso a los registros de tareas. Se recomienda a los usuarios actualizar a Apache Airflow 3.1.7 o posterior, lo que resuelve este problema.

11 Feb 2026, 18:30

Type Values Removed Values Added
References () https://github.com/apache/airflow/pull/60412 - () https://github.com/apache/airflow/pull/60412 - Issue Tracking, Patch
References () https://lists.apache.org/thread/gdb7vffhpmrj5hp1j0oj1j13o4vmsq40 - () https://lists.apache.org/thread/gdb7vffhpmrj5hp1j0oj1j13o4vmsq40 - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/02/09/2 - () http://www.openwall.com/lists/oss-security/2026/02/09/2 - Mailing List, Third Party Advisory
First Time Apache airflow
Apache
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

09 Feb 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/02/09/2 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

09 Feb 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 11:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22922

Mitre link : CVE-2026-22922

CVE.ORG link : CVE-2026-22922


JSON object : View

Products Affected

apache

  • airflow
CWE
CWE-648

Incorrect Use of Privileged APIs