CVE-2026-40690

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

27 Apr 2026, 12:24

Type Values Removed Values Added
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
References () https://github.com/apache/airflow/pull/65273 - () https://github.com/apache/airflow/pull/65273 - Issue Tracking, Patch
References () https://lists.apache.org/thread/bqt7y4g2cpj396b0sd20lv510ff19ndl - () https://lists.apache.org/thread/bqt7y4g2cpj396b0sd20lv510ff19ndl - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/04/24/4 - () http://www.openwall.com/lists/oss-security/2026/04/24/4 - Mailing List, Third Party Advisory
First Time Apache airflow
Apache

24 Apr 2026, 17:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/04/24/4 -

24 Apr 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

24 Apr 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-24 13:16

Updated : 2026-04-27 12:24


NVD link : CVE-2026-40690

Mitre link : CVE-2026-40690

CVE.ORG link : CVE-2026-40690


JSON object : View

Products Affected

apache

  • airflow
CWE
CWE-1220

Insufficient Granularity of Access Control