CVE-2026-32228General(apache / airflow)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache airflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 104-1704-1804-19
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-171
General1
2026-04-181
Patch1
2026-04-191
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-30898: Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf https://www.openwall.com/lists/oss-security/2026/04/17/7 CVE-2026-32228: Apache Airflow: Users with asset materialization permissions could trigger Dags they had no access to https://www.openwall.com/lists/oss-security/2026/04/17/8

    Post summary

    The post announces two new Apache Airflow CVEs, detailing a BashOperator shell injection via dag_run.conf and an access-control flaw that permits unauthorized DAG execution.

    10000193
    4.5K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-32228 UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. https://www.cve.org/CVERecord?id=CVE-2026-32228

    Post summary

    CVE-2026-32228 permits users with asset materialize permission to trigger DAGs they normally couldn’t access; upgrading to Airflow 3.2.0 mitigates the vulnerability.

    0000046
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32228 CVE-2026-32228 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32228

    Post summary

    The text only lists CVE‑2026‑32228 and a link to a vulnerability database, offering no further context or technical details.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more