CVE-2026-32228: Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
(updated )
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-32228 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →