CVE-2026-24098Disclosure(apache / airflow)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-09: 3Technical Details · 2026-02-09: 302-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-22922: Apache Airflow: Airflow externalLogUrl Permission Bypass https://www.openwall.com/lists/oss-security/2026/02/09/2 CVE-2026-24098: Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors https://www.openwall.com/lists/oss-security/2026/02/09/3

    Post summary

    The text lists two new Apache Airflow CVEs with brief technical details but offers no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    100741.3K
    4.4K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24098 Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generate… https://www.cve.org/CVERecord?id=CVE-2026-24098

    Post summary

    CVE-2026-24098 affects Apache Airflow versions prior to 3.1.7, permitting authenticated UI users with permissions to specific Dags to view import errors.

    00010316
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24098 Information Disclosure in Apache Airflow Versions Before 3.1.7 Allows Unauthorized DAG Error Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24098

    Post summary

    The text announces CVE-2026-24098 as an information disclosure flaw in Apache Airflow <3.1.7 that permits unauthorized access to DAG error details, with no PoC, exploit, patch, or false‑positive claim mentioned.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more