VYPR
High severity8.1NVD Advisory· Published Jul 13, 2026· Updated Sep 16, 2026

CVE-2026-59245

CVE-2026-59245

Description

In the Apache Airflow FAB auth manager, a DAG whose dag_id is DAGs collided with the global all-DAGs permission resource name produced by resource_name(), so a user granted per-DAG access_control on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named DAGs exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to apache-airflow-providers-fab 3.7.2 or later, which disambiguates the resource-name collision.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*range: <3.7.2
    • (no CPE)range: before 3.7.2
  • Apache/Airflowllm-fuzzy
    Range: before 3.7.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.