CVE-2026-38743Disclosure(apache / airflow)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for DAGs outside their authorized scope. Because HITL prompts and TaskInstance fields routinely carry operator parameters and free-form context attached to a task, the leak widens visibility of DAG-run data beyond the intended per-DAG RBAC boundary for every authenticated user. Users are recommended to upgrade to version 3.2.1 , which fixes this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1220

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-28: 104-2404-2504-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets5 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Airflow CVE-2026-38743: Dags endpoint might provide access to otherwise inaccessible entities https://www.openwall.com/lists/oss-security/2026/04/24/3 CVE-2026-40690: Assets graph view bypasses DAG level access control displaying unrelated topologies and names to unauthorized users https://www.openwall.com/lists/oss-security/2026/04/24/4

    Post summary

    The text discloses two Apache Airflow CVEs that permit unauthorized entity access and bypass DAG-level access controls.

    00000163
    4.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-38743 The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user wit… https://www.cve.org/CVERecord?id=CVE-2026-38743

    Post summary

    CVE‑2026‑38743 reveals a missing per‑DAG access control in Airflow’s /ui/dags endpoint, enabling logged‑in users to view all Human‑in‑the‑Loop and TaskInstance records. No PoC, exploit, or patch details are disclosed in this snippet.

    0000080
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-38743 Unauthorized Information Disclosure in Apache Airflow /ui/dags En... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-38743 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new CVE‑2026‑38743 vulnerability in Apache Airflow’s /ui/dags endpoint, causing unauthorized information disclosure, has been announced with a link to a vulnerability details page but no PoC, exploit, or patch information.

    0000035
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more