Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Mon, 01 Jun 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, while the collection endpoint `GET /api/v2/eventLogs` applied per-Dag scoping. An authenticated UI/API user with audit-log read permission for one Dag could retrieve audit-log entries for any other Dag by guessing or enumerating the numeric event log ID. Affects deployments that rely on per-Dag audit-log scoping. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. | |
| Title | Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter | |
| Weaknesses | CWE-639 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-02T15:50:10.266Z
Reserved: 2026-05-18T15:42:29.004Z
Link: CVE-2026-46764
Updated: 2026-06-01T07:48:02.639Z
Status : Modified
Published: 2026-06-01T09:16:20.073
Modified: 2026-06-02T17:16:35.047
Link: CVE-2026-46764
No data.
OpenCVE Enrichment
Updated: 2026-06-01T19:30:06Z