CVE-2026-26929Disclosure(apache / airflow)

LOWCVSS 6.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version metadata of DAGs that the requester is not authorized to access is returned. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-17: 4Technical Details · 2026-03-17: 303-17
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Airflow CVE-2026-26929: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata https://www.openwall.com/lists/oss-security/2026/03/17/4 CVE-2026-28563: DAG authorization bypass https://www.openwall.com/lists/oss-security/2026/03/17/5

    Post summary

    Two new Apache Airflow CVEs are announced: one permits wildcard DagVersion listing that bypasses per‑DAG RBAC and leaks metadata, the other allows DAG authorization bypass. No exploit code, patch, or evidence of active exploitation is provided.

    00010257
    4.4K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26929 Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to … https://www.cve.org/CVERecord?id=CVE-2026-26929

    Post summary

    The note identifies a missing authorization check in Airflow's DagVersion listing API, potentially exposing privileged data, but there is no mention of PoC, exploit, patch, or active use in the wild.

    00000129
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-26929 🚨 Risk Level: Unknown 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-26929 #CVE-2026-26929 #CVE  #Apache #CyberSecurity #InfoSec https://t.co/b4sZ57ZHp4

    Post summary

    A tweet announces the existence of a new CVE-2026-26929 affecting Apache, noting an unknown risk level and providing a link to the NVD entry for details.

    0000035
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-26929 - Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata Intel Report: https://ift.tt/BuYhwC1

    Post summary

    The message announces a newly disclosed CVE targeting Apache Airflow, describing how wildcard DagVersion listings bypass RBAC and leak metadata, but it provides no PoC, exploit, or patch details.

    0000055
    336 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more