THREAT OPS › Threat News › CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)
CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)
<p>Posted by Rahul Vats on Sep 17</p>Severity: low <br /> <br /> Affected versions:<br /> <br /> - Apache Airflow before 3.3.2<br /> <br /> Description:<br /> <br /> Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of <br /> `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued a
Indicators of compromise
- CVE-2026-75157cve
Original source: https://seclists.org/oss-sec/2026/q3/820