← Retour à la recherche de CVE

CVE-2026-41084

Apache Airflow

Description

A bug in Apache Airflow-s bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path while operating on the `dag_id` / `dag_run_id` extracted from request-body entity fields. An authenticated UI/API user with edit permission on one Dag could mutate Task Instance state in any other Dag by keeping the authorized Dag-s ID in the URL path and naming the target Dag-s IDs in the request body entities. Affects deployments that rely on per-Dag edit-scope to keep Task Instance state isolated between teams. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.

CVSS 7.5EPSS 0.47600000000000003%Risque 0.78
Voir la source
Publication
2026-06-01 09:16:18
Versions concernées
<3.2.2
Type
Core software
Dernière modification
2026-07-21 19:10:00
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N