Incorrect Authorization Affecting apache-airflow-core package, versions [,3.3.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWCORE-19964067
  • published20 Sept 2026
  • disclosed18 Sept 2026
  • creditn0mi1k

Introduced: 18 Sep 2026

NewCVE-2026-75157  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade apache-airflow-core to version 3.3.2 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization via the delete_asset_queued_events, delete_dag_asset_queued_events, and related queued-events DELETE routes in airflow/api_fastapi/core_api/routes/public/assets.py. An attacker can delete a DAG’s queued asset events by sending a DELETE request to these endpoints while holding only DAG read access and the global asset-delete permission. This lets an authenticated user silently suppress asset-triggered scheduling for a DAG they can read but not edit. In affected deployments, DAG runs stop being queued from those asset events, breaking the DAG’s automatic scheduling behavior.

CVSS Base Scores

version 4.0
version 3.1