
Apache Airflow CVE-2026-38743: Dags endpoint might provide access to otherwise inaccessible entities https://www.openwall.com/lists/oss-security/2026/04/24/3 CVE-2026-40690: Assets graph view bypasses DAG level access control displaying unrelated topologies and names to unauthorized users https://www.openwall.com/lists/oss-security/2026/04/24/4
Post summary
Two new Apache Airflow CVEs are disclosed, allowing unauthorized users to access restricted entities via the Dags endpoint and graph view, but no exploitation code, PoC, or patch information is provided.


