CVE-2026-32228

CVE-2026-32228: Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-863 · Incorrect authorization
Published April 18, 2026
Last update April 20, 2026

CVSS base score