CVE-2026-32228

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:35

Type Values Removed Values Added
References () https://lists.apache.org/thread/s7c75txgt4qf2rofcn43szfwgcrzy0nj - Vendor Advisory, Mailing List () https://lists.apache.org/thread/s7c75txgt4qf2rofcn43szfwgcrzy0nj - Mailing List, Vendor Advisory

21 Apr 2026, 12:54

Type Values Removed Values Added
First Time Apache airflow
Apache
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
References () https://github.com/apache/airflow/pull/63338 - () https://github.com/apache/airflow/pull/63338 - Issue Tracking
References () https://lists.apache.org/thread/s7c75txgt4qf2rofcn43szfwgcrzy0nj - () https://lists.apache.org/thread/s7c75txgt4qf2rofcn43szfwgcrzy0nj - Vendor Advisory, Mailing List
References () http://www.openwall.com/lists/oss-security/2026/04/17/8 - () http://www.openwall.com/lists/oss-security/2026/04/17/8 - Mailing List, Third Party Advisory

20 Apr 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

18 Apr 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-18 07:16

Updated : 2026-06-17 10:35


NVD link : CVE-2026-32228

Mitre link : CVE-2026-32228

CVE.ORG link : CVE-2026-32228


JSON object : View

Products Affected

apache

  • airflow
CWE
CWE-863

Incorrect Authorization