Junglewise Threat Intelligence

CVE-2026-59245: Apache Airflow FAB provider privilege escalation via DAG name collision

CVE-2026-59245 · Severity: info · CVSS 0 · Published 2026-07-13

Technologies: Apache Software Foundation Airflow FAB Provider. Vendors: Apache Software Foundation.

Executive brief

Apache Airflow, a platform used to schedule and monitor workflows, contains a flaw in its FAB authentication manager. If a workflow (DAG) is specifically named 'DAGs', the system confuses it with the global permission setting for all workflows. As a result, a user who is only supposed to have access to that one specific workflow is accidentally granted full read and edit access to every workflow in the entire system.

Technical details

A privilege escalation vulnerability exists in the Apache Airflow FAB auth manager due to a resource name collision in the `resource_name()` function. When a DAG is created with the ID `DAGs`, the auth manager fails to distinguish it from the global 'all-DAGs' permission resource. Consequently, granting a low-privileged user `access_control` permissions on a DAG named `DAGs` silently elevates their privileges to include global read/edit access across all DAGs in the environment. The fix, introduced in `apache-airflow-providers-fab` 3.7.2, removes a short-circuit logic that allowed bare reserved resource names to bypass the standard `DAG:<dag_id>` prefixing.

Affected products

  • Apache Software Foundation Apache Airflow FAB provider < 3.7.2

Timeline

  • 2026-06-28: disclosed: Initial pull request submitted to Apache Airflow repository
  • 2026-07-06: patched: Fix merged into main branch
  • 2026-07-13: advisory: CVE published by Apache Software Foundation

References

Related threats