LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-28563

apache · airflow

Published
CVSS4.3
Severitymedium
WeaknessCWE-732
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-28563

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-28563.