← לוח פגיעויות

CVE-2026-32228

גבוהה 7.5

תיאור (מקור, אנגלית)

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-28/7/2026
CWE
CWE-863

מוצרים מושפעים

apache: airflow

קישורים