Executive brief
Apache Airflow is an open-source platform used to schedule and monitor complex workflows (DAGs). A security flaw in the event logging system allowed users with limited access to view audit logs for workflows they were not authorized to see. By guessing or cycling through log IDs, an authenticated user could potentially expose sensitive operational data or metadata about other business processes.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Apache Airflow REST API. While the collection endpoint `GET /api/v2/eventLogs` correctly filters results based on per-DAG (Directed Acyclic Graph) permissions, the detail endpoint `GET /api/v2/eventLogs/{event_log_id}` only performed a global audit-log permission check. This allowed an authenticated attacker with read access to at least one DAG's audit logs to retrieve any other log entry by enumerating the numeric `event_log_id`. The root cause was the lack of DAG-specific ownership verification during direct ID lookups. The issue is resolved in version 3.2.2 by introducing a check that resolves the DAG ID from the log entry and validates the user's access against that specific DAG.
Affected products
- Apache Airflow < 3.2.2
Timeline
- 2026-05-18: other: Fix PR submitted to Apache Airflow repository
- 2026-05-31: disclosed: Public disclosure on oss-security mailing list
- 2026-06-01: advisory: GitHub and NVD advisories published