CVE-2026-32228: Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
Published Apr 17, 2026
·Updated
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.
Affected Software
3 affected componentsFixes available
Apache Airflow<3.2.0
Apache Airflow>=3.0.0<3.2.0
pip/apache-airflow-core>=3.0.0<3.2.0
3.2.0
Event History
Apr 18, 2026
CVE Published
via MITRE·06:19 AM
Data Sourced
via MITRE·06:19 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-32228?
CVE-2026-32228 is categorized as a moderate severity vulnerability.
2
How do I fix CVE-2026-32228?
To fix CVE-2026-32228, users should upgrade to Apache Airflow version 3.2.0 or later.
3
What impact does CVE-2026-32228 have on Apache Airflow users?
CVE-2026-32228 allows users with asset materialization permissions to trigger DAGs they should not have access to, potentially leading to unauthorized actions.
4
Which versions of Apache Airflow are affected by CVE-2026-32228?
Versions of Apache Airflow from 3.0.0 up to, but not including, 3.2.0 are affected by CVE-2026-32228.
5
Are there any recommended practices to prevent CVE-2026-32228?
It is recommended to regularly update to the latest version of Apache Airflow and review user permissions to mitigate risks associated with CVE-2026-32228.