Apache Airflow Asset Materialization Permission Vulnerability

Vulnerability

A vulnerability exists in Apache Airflow versions 3.0.0 prior to 3.2.0, allowing users with asset materialization permissions to trigger DAGs they do not have access to. This issue has been addressed in Airflow version 3.2.0.

Impact

Exploitation of this vulnerability could lead to unauthorized triggering of DAGs, potentially causing unintended data processing or workflow execution.

Remediation

Users are advised to upgrade to Apache Airflow version 3.2.0, which addresses this vulnerability.

Added: Apr 18, 2026, 7:19 AM
Updated: Apr 18, 2026, 7:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.