Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59245

Опубликовано: 13 июл. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

In the Apache Airflow FAB auth manager, a DAG whose dag_id is DAGs collided with the global all-DAGs permission resource name produced by resource_name(), so a user granted per-DAG access_control on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named DAGs exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to apache-airflow-providers-fab 3.7.2 or later, which disambiguates the resource-name collision.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*
Версия до 3.7.2 (исключая)

EPSS

Процентиль: 46%
0.00599
Низкий

8.1 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.1
github
около 1 месяца назад

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.

EPSS

Процентиль: 46%
0.00599
Низкий

8.1 High

CVSS3

Дефекты

CWE-269