Loading
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.
Use CWE-863, Apache vendor hub and Airflow product page to widen CVE-2026-32228 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-30898, CVE-2026-33858 and CVE-2025-54550 for nearby disclosures in the same product family.