THREAT OPS › Threat News › [NVD] CVE-2026-59245 (HIGH 8.1) — In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privile
[NVD] CVE-2026-59245 (HIGH 8.1) — In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privile
CVE-2026-59245 CVSS: 8.1 HIGH Published: 2026-07-13T16:16:41.880
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG nam
Indicators of compromise
- CVE-2026-59245cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59245