High severity8.1NVD Advisory· Published Jul 13, 2026· Updated Sep 16, 2026
CVE-2026-59245
CVE-2026-59245
Description
In the Apache Airflow FAB auth manager, a DAG whose dag_id is DAGs collided with the global all-DAGs permission resource name produced by resource_name(), so a user granted per-DAG access_control on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named DAGs exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to apache-airflow-providers-fab 3.7.2 or later, which disambiguates the resource-name collision.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*range: <3.7.2
- (no CPE)range: before 3.7.2
Patches
Vulnerability mechanics
References
3- github.com/apache/airflow/pull/69106nvdIssue TrackingPatch
- www.openwall.com/lists/oss-security/2026/07/13/4nvdMailing ListThird Party Advisory
- lists.apache.org/thread/70f37q3mwov1vm3zolrfxlzds278c78hnvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.