Description
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.
Problem types
CWE-863: Incorrect Authorization
Product status
3.0.0 (semver) before 3.2.0
Credits
Masamune - Unit515 OPSWAT
Ahmad Abuzaid
Pierre Jeambrun
References
www.openwall.com/lists/oss-security/2026/04/17/8
github.com/apache/airflow/pull/63338
lists.apache.org/thread/s7c75txgt4qf2rofcn43szfwgcrzy0nj