CVE-2026-28563Disclosure(apache / airflow)

LOWCVSS 4.3 · MEDIUM

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-17: 5Technical Details · 2026-03-17: 403-17
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Airflow CVE-2026-26929: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata https://www.openwall.com/lists/oss-security/2026/03/17/4 CVE-2026-28563: DAG authorization bypass https://www.openwall.com/lists/oss-security/2026/03/17/5

    Post summary

    Two new Apache Airflow CVEs are announced—CVE‑2026‑26929 involving wildcard DagVersion listing bypass and CVE‑2026‑28563 involving DAG authorization bypass—alongside links to community discussion threads, but no PoC, exploit, patch, or false‑positive claim is provided.

    00010257
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28563 Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an au… https://www.cve.org/CVERecord?id=CVE-2026-28563

    Post summary

    Apache Airflow versions 3.1.0 through 3.1.7 expose the full DAG dependency graph via the /ui/dependencies endpoint, potentially leaking data from unauthorized DAGs.

    00000130
    56.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-28563 🚨 Risk Level: Unknown 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28563 #CVE-2026-28563 #CVE  #Apache #CyberSecurity #InfoSec https://t.co/BQ6HHhLVQq

    Post summary

    The tweet announces a new CVE (CVE‑2026‑28563) affecting Apache but provides no technical details, exploits, or mitigation advice.

    0000037
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28563 - Apache Airflow: DAG authorization bypass Intel Report: https://ift.tt/SEvLney

    Post summary

    The alert announces CVE-2026-28563, a DAG authorization bypass in Apache Airflow, and provides an Intel report link, but offers no further exploit or mitigation details.

    0000034
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28563 Information Disclosure in Apache Airflow 3.1.0-3.1.7 DAG Dependencies Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28563

    Post summary

    A newly reported information disclosure vulnerability (CVE-2026-28563) affects Apache Airflow 3.1.0‑3.1.7’s DAG dependencies endpoint; no PoC, exploit, or patch details are disclosed.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more