CVE-2026-75158: Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter

Published Sep 21, 2026
·
Updated

Apache Airflow's /assets/events API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event timestamps — for Dags they have no permission to see. Because the filter was also absent from the count query, totalentries and pagination disclosed the existence of hidden Dags even without inspecting individual rows. Deployments are affected whenever per-Dag access control is used to separate teams or tenants; no special configuration is required. Upgrade to apache-airflow 3.3.2 or later.

Affected Software

1 affected component
Apache Apache Airflow<3.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Airflow to a version that resolves this vulnerability.

    Fixed in 3.3.2

Event History

Sep 21, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to meaningful unauthorized disclosure?

Deployments that use per-Dag access control to separate teams or tenants are affected. Any authenticated user with asset-read access can enumerate events for Dags they are not authorized to view.

2

What information can an unauthorized user obtain?

The API can disclose asset-event metadata including source Dag IDs, task IDs, run IDs, and event timestamps. The total_entries value and pagination can also reveal that hidden Dags exist, even without examining returned event rows.

3

Does exploitation require a special configuration or elevated privileges?

No special configuration is required. An attacker needs an authenticated account with asset-read access; they do not need permission to read the affected Dags.

4

What version resolves the issue?

Upgrade to Apache Airflow 3.3.2 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203