
Apache Airflow CVE-2026-26929: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata https://www.openwall.com/lists/oss-security/2026/03/17/4 CVE-2026-28563: DAG authorization bypass https://www.openwall.com/lists/oss-security/2026/03/17/5
Post summary
Two new Apache Airflow CVEs are announced: one permits wildcard DagVersion listing that bypasses per‑DAG RBAC and leaks metadata, the other allows DAG authorization bypass. No exploit code, patch, or evidence of active exploitation is provided.



