CVE-2026-22922

CVE-2026-22922: Apache Airflow: Airflow externalLogUrl Permission Bypass

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-648
Published February 9, 2026
Last update February 9, 2026

CVSS base score

What the vulnerability does

Description

Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.

Key dates

Disclosure timeline

February 9, 2026 CVE published
February 9, 2026 Record updated