No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 21 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Mon, 21 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event timestamps — for Dags they have no permission to see. Because the filter was also absent from the count query, `total_entries` and pagination disclosed the existence of hidden Dags even without inspecting individual rows. Deployments are affected whenever per-Dag access control is used to separate teams or tenants; no special configuration is required. Upgrade to apache-airflow 3.3.2 or later. | |
| Title | Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter | |
| Weaknesses | CWE-200 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-21T18:09:31.208Z
Reserved: 2026-08-17T18:58:38.671Z
Link: CVE-2026-75158
Updated: 2026-09-21T15:26:41.470Z
Status : Awaiting Analysis
Published: 2026-09-21T15:17:31.360
Modified: 2026-09-21T18:10:30.343
Link: CVE-2026-75158
No data.
OpenCVE Enrichment
Updated: 2026-09-21T17:45:17Z