Executive brief
Apache Airflow, a platform used to schedule and monitor workflows, contains a flaw in its FAB authentication manager. If a workflow (DAG) is specifically named 'DAGs', the system confuses it with the global permission setting for all workflows. As a result, a user who is only supposed to have access to that one specific workflow is accidentally granted full read and edit access to every workflow in the entire system.
Technical details
A privilege escalation vulnerability exists in the Apache Airflow FAB auth manager due to a resource name collision in the `resource_name()` function. When a DAG is created with the ID `DAGs`, the auth manager fails to distinguish it from the global 'all-DAGs' permission resource. Consequently, granting a low-privileged user `access_control` permissions on a DAG named `DAGs` silently elevates their privileges to include global read/edit access across all DAGs in the environment. The fix, introduced in `apache-airflow-providers-fab` 3.7.2, removes a short-circuit logic that allowed bare reserved resource names to bypass the standard `DAG:<dag_id>` prefixing.
Affected products
- Apache Software Foundation Apache Airflow FAB provider < 3.7.2
Timeline
- 2026-06-28: disclosed: Initial pull request submitted to Apache Airflow repository
- 2026-07-06: patched: Fix merged into main branch
- 2026-07-13: advisory: CVE published by Apache Software Foundation