ZeroHour

CVE-2026-32228

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
Description

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

Vendors
apache
Products
airflow
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.