Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 14, 2026
Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)
CVE-2026-59245
Description
In the Apache Airflow FAB auth manager, a DAG whose dag_id is DAGs collided with the global all-DAGs permission resource name produced by resource_name(), so a user granted per-DAG access_control on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named DAGs exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to apache-airflow-providers-fab 3.7.2 or later, which disambiguates the resource-name collision.
Affected products
2- Range: >=3.7.2
Patches
Vulnerability mechanics
References
2- github.com/apache/airflow/pull/69106mitrepatch
- lists.apache.org/thread/70f37q3mwov1vm3zolrfxlzds278c78hmitrevendor-advisory
News mentions
0No linked articles in our index yet.