https://seclists.org/oss-sec/2026/q2/742: CVE-2026-41014: Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
Published May 31, 2026
·Updated
Affected Software
1 affected component
pypi/apache-airflow>=3.2.0<3.2.2
Frequently Asked Questions
1
What is the severity of CVE-2026-41014?
CVE-2026-41014 has a low severity rating.
2
What versions of Apache Airflow are affected by CVE-2026-41014?
Apache Airflow versions 3.2.0 before 3.2.2 are affected by CVE-2026-41014.
3
What does CVE-2026-41014 exploit?
CVE-2026-41014 exploits a per-DAG RBAC bypass on the /ui/partitioned_dag_runs endpoints.
4
How do I fix CVE-2026-41014?
To fix CVE-2026-41014, update Apache Airflow to version 3.2.2 or later.
5
What type of access control issue does CVE-2026-41014 involve?
CVE-2026-41014 involves asset-level access control rather than per-DAG authorization.