https://seclists.org/oss-sec/2026/q2/213: CVE-2026-40690: Apache Airflow: Assets graph view bypasses DAG level access control displaying unlated topologies and all DAGs names to unauthorized users
Published Apr 24, 2026
·Updated
Affected Software
1 affected component
Apache Apache Airflow<3.2.1
Frequently Asked Questions
1
What is the severity of CVE-2026-40690?
The severity of CVE-2026-40690 is classified as low.
2
What versions of Apache Airflow are affected by CVE-2026-40690?
Apache Airflow versions before 3.2.1 are affected by CVE-2026-40690.
3
What is the main issue described in CVE-2026-40690?
CVE-2026-40690 involves the asset graph view bypassing DAG level access control, allowing unauthorized users to see unrelatable topologies.
4
How do I fix CVE-2026-40690?
To fix CVE-2026-40690, upgrade to Apache Airflow version 3.2.1 or later.
5
What security implications does CVE-2026-40690 have?
CVE-2026-40690 could potentially expose sensitive information about DAGs to unauthorized users.