THREATOPS
THREAT OPSThreat News › CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)

CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)

medoss_secPublished 2026-09-18

<p>Posted by Rahul Vats on Sep 17</p>Severity: low <br /> <br /> Affected versions:<br /> <br /> - Apache Airflow before 3.3.2<br /> <br /> Description:<br /> <br /> Apache Airflow&apos;s asset queued-events DELETE endpoints checked the caller&apos;s Dag-axis permission with `READ` instead of <br /> `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag&apos;s queued a

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/820