CVE-2026-75158 Overview
Apache Airflow contains an information disclosure vulnerability in its /assets/events REST API endpoint. The endpoint returns asset events for every Directed Acyclic Graph (DAG) in the deployment without filtering results against the caller's authorization scope. Any authenticated user with asset-read access can enumerate asset events belonging to DAGs they cannot otherwise view. Disclosed fields include the source DAG identifier, task identifier, run identifier, and event timestamps. The count query is also unfiltered, so total_entries and pagination metadata leak the existence of hidden DAGs even when row content is not inspected. Deployments that rely on per-DAG access control to isolate teams or tenants are affected without any special configuration. The issue is tracked under CWE-200: Exposure of Sensitive Information to an Unauthorized Actor.
Critical Impact
Authenticated tenants can enumerate DAG identifiers, task identifiers, run identifiers, and event timestamps for workflows owned by other teams, breaking multi-tenant isolation.
Affected Products
- Apache Airflow versions prior to 3.3.2
- Airflow deployments configured with per-DAG access control for team or tenant separation
- Any Airflow REST API consumer relying on /assets/events authorization boundaries
Discovery Timeline
- 2026-09-21 - CVE-2026-75158 published to the National Vulnerability Database
- 2026-09-21 - Coordinated disclosure posted to the OpenWall OSS-Security list
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-75158
Vulnerability Analysis
The vulnerability is a broken access control flaw in the Airflow REST API layer. When a client requests /assets/events, the handler queries the asset event store and serializes matching rows without applying the per-DAG authorization filter that other Airflow endpoints enforce. The same omission is present in the count query used to compute pagination metadata. As a result, the API returns event records tied to DAGs the caller is not permitted to read, and the total_entries value discloses the number of hidden events even when the caller only inspects pagination headers. See the upstream fix in the Apache Airflow pull request and the Apache announcement thread for further context.
Root Cause
The root cause is a missing authorization predicate in the /assets/events query builder. Airflow's per-DAG access control model expects each endpoint to intersect result sets with the DAGs the caller is authorized to read. The /assets/events handler and its associated count query did not apply this intersection, exposing all asset events regardless of caller permissions.
Attack Vector
Exploitation requires only an authenticated Airflow account with asset-read permission. The attacker issues an HTTP GET request to /assets/events with optional pagination parameters. The response contains asset event objects for DAGs across the deployment, including DAG identifiers, task identifiers, run identifiers, and event timestamps. Iterating pagination pages allows full enumeration of asset event history for other tenants.
No verified proof-of-concept code has been published. The vulnerability is described in prose in the upstream advisory; readers should consult the Apache Airflow pull request 71741 for the corrective code changes.
Detection Methods for CVE-2026-75158
Indicators of Compromise
- Unusual volumes of authenticated GET requests to /assets/events originating from a single user or API token.
- Pagination walks with high offset or limit values against /assets/events from accounts that historically only access a small subset of DAGs.
- API responses returning DAG identifiers that fall outside the caller's assigned role or team scope.
Detection Strategies
- Enable Airflow API audit logging and alert on /assets/events requests where the responding record set includes DAG identifiers not present in the caller's role bindings.
- Correlate API access logs with role-to-DAG mappings to flag cross-tenant reads.
- Baseline normal per-user request rates against /assets/events and alert on statistical deviations.
Monitoring Recommendations
- Forward Airflow webserver and API logs to a centralized analytics platform for long-term retention and correlation.
- Track distinct DAG identifiers observed per API token per day and alert on sudden expansion of the set.
- Monitor for enumeration patterns such as sequential pagination or repeated queries with incrementing offsets.
How to Mitigate CVE-2026-75158
Immediate Actions Required
- Upgrade all Apache Airflow deployments to version 3.3.2 or later.
- Audit recent access logs for /assets/events requests from accounts that should not have visibility into other teams' DAGs.
- Rotate API tokens for any accounts that may have been used to enumerate asset events across tenant boundaries.
Patch Information
The fix is included in Apache Airflow 3.3.2 and merged upstream in pull request 71741. The patch adds the missing per-DAG authorization filter to both the /assets/events list handler and its count query so that unauthorized DAGs no longer appear in results or pagination totals.
Workarounds
- Restrict network access to the /assets/events endpoint using a reverse proxy or API gateway while the upgrade is scheduled.
- Temporarily revoke asset-read permissions from roles that do not require asset event visibility.
- Segment sensitive workloads into separate Airflow deployments where multi-tenant isolation is a hard requirement.
# Upgrade Apache Airflow to the patched release
pip install --upgrade "apache-airflow==3.3.2"
# Verify the installed version
airflow version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
