CVE-2026-75157 Overview
Apache Airflow contains a broken access control flaw in the asset queued-events DELETE endpoints. The endpoints validate the caller's Dag-axis permission with READ instead of EDIT. Any authenticated user with read access to a Dag can delete that Dag's queued asset events. This silently suppresses asset-triggered scheduling for the affected Dag. Deployments are affected whenever asset-triggered scheduling is enabled and Dag read access is broader than Dag edit access, which reflects standard Role-Based Access Control (RBAC) arrangements. No special configuration is required to exploit the flaw. The issue is tracked as CWE-863: Incorrect Authorization.
Critical Impact
Authenticated users with read-only Dag permissions can suppress asset-triggered scheduling by deleting queued asset events, breaking downstream data pipeline execution.
Affected Products
- Apache Airflow versions prior to 3.3.2
- Deployments using asset-triggered scheduling
- Environments where Dag READ permission is granted more broadly than Dag EDIT permission
Discovery Timeline
- 2026-09-18 - CVE-2026-75157 published to NVD
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-75157
Vulnerability Analysis
The flaw resides in Apache Airflow's REST API handlers for asset queued-events. Deleting a queued asset event is a state-changing operation that removes pending triggers for a Dag. The affected DELETE endpoints enforce authorization by checking the caller's Dag-axis permission as READ rather than EDIT. This mismatch allows any authenticated user who can view a Dag to delete queued asset events tied to that Dag.
Asset-triggered scheduling in Airflow uses queued events to fire downstream Dag runs when upstream data assets update. Removing these events prevents the scheduler from initiating dependent runs. The action produces no error to the caller and no explicit alert to Dag owners. Data pipelines silently stop executing on their expected triggers, and downstream consumers receive stale or missing data.
Root Cause
The root cause is an authorization decision that gates a write operation behind a read permission. The endpoint implementation invokes the permission check with the READ action constant instead of EDIT. This falls under CWE-863: Incorrect Authorization, where the access control logic executes but evaluates the wrong permission for the operation being performed.
Attack Vector
An attacker requires authenticated access to the Airflow web server or API and read permission on at least one Dag that uses asset-triggered scheduling. The attacker calls the queued-events DELETE endpoint for the target Dag. Because Airflow evaluates the request against the caller's READ grant, the delete succeeds. Repeated calls can persistently suppress scheduling for any Dag the attacker can read. Details of the corrected authorization check are available in the Apache Airflow Pull Request #71736 and the Apache mailing list disclosure.
Detection Methods for CVE-2026-75157
Indicators of Compromise
- Unexpected DELETE requests to asset queued-events API endpoints in Airflow web server access logs
- Sudden absence of asset-triggered Dag runs despite upstream asset updates
- Audit log entries showing queued asset event deletions performed by accounts with only Dag READ roles
- API calls to queued-events endpoints originating from users outside the Dag owner group
Detection Strategies
- Correlate Airflow API access logs with RBAC role assignments to flag DELETE calls from read-only principals
- Compare expected asset-trigger Dag run counts against actual scheduler activity to identify suppression
- Alert on any DELETE requests targeting /api/v1/dags/{dag_id}/datasets/queuedEvent or equivalent asset queued-event paths
- Baseline normal API usage per user role and flag deviations, especially write-verb calls from viewer accounts
Monitoring Recommendations
- Enable and centralize Airflow audit logs, forwarding them to a SIEM for correlation with authentication data
- Track scheduler metrics for asset-triggered runs and alert on drops that do not match upstream activity
- Review RBAC role assignments regularly to identify users with unexpectedly broad Dag read access
- Monitor the Airflow REST API for anomalous DELETE traffic patterns and integrate findings with existing detection pipelines
How to Mitigate CVE-2026-75157
Immediate Actions Required
- Upgrade Apache Airflow to version 3.3.2 or later on all deployments using asset-triggered scheduling
- Audit RBAC role assignments and restrict Dag READ grants to users who genuinely require visibility
- Review recent Airflow audit logs for unauthorized DELETE calls against asset queued-events endpoints
- Validate that expected asset-triggered Dag runs have executed during the exposure window
Patch Information
The fix is included in Apache Airflow 3.3.2. The corrected authorization check replaces the READ permission validation with an EDIT permission check on the asset queued-events DELETE endpoints. Full details of the code change are available in Apache Airflow Pull Request #71736 and the Openwall OSS Security advisory.
Workarounds
- Restrict Dag READ permissions to a smaller trusted user population until the upgrade is applied
- Place the Airflow API behind a reverse proxy that blocks DELETE requests to queued-events paths for non-administrative users
- Disable asset-triggered scheduling on sensitive Dags where operational impact from suppression would be significant
- Increase monitoring of scheduler behavior and audit logs to detect suppression attempts before patching completes
# Upgrade Apache Airflow to the patched release
pip install --upgrade "apache-airflow>=3.3.2"
# Verify the installed version
airflow version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
