Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 21 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 21 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Mon, 21 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event timestamps — for Dags they have no permission to see. Because the filter was also absent from the count query, `total_entries` and pagination disclosed the existence of hidden Dags even without inspecting individual rows. Deployments are affected whenever per-Dag access control is used to separate teams or tenants; no special configuration is required. Upgrade to apache-airflow 3.3.2 or later. | |
| Title | Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter | |
| Weaknesses | CWE-200 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-21T18:09:31.208Z
Reserved: 2026-08-17T18:58:38.671Z
Link: CVE-2026-75158
Updated: 2026-09-21T18:09:31.208Z
Status : Awaiting Analysis
Published: 2026-09-21T15:17:31.360
Modified: 2026-09-21T19:17:09.580
Link: CVE-2026-75158
No data.
OpenCVE Enrichment
Updated: 2026-09-21T17:45:17Z