CVE-2026-24098

A

pache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

11 Feb 2026, 18:30

Type Values Removed Values Added
References () https://github.com/apache/airflow/pull/60801 - () https://github.com/apache/airflow/pull/60801 - Issue Tracking, Patch
References () https://lists.apache.org/thread/nx96435v77xdst7ls5lk57kqvqyj095x - () https://lists.apache.org/thread/nx96435v77xdst7ls5lk57kqvqyj095x - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/02/09/3 - () http://www.openwall.com/lists/oss-security/2026/02/09/3 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
First Time Apache airflow
Apache

09 Feb 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/02/09/3 -

09 Feb 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

09 Feb 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 11:16

Updated : 2026-02-11 18:30


NVD link : CVE-2026-24098

Mitre link : CVE-2026-24098

CVE.ORG link : CVE-2026-24098


JSON object : View

Products Affected
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor