Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pm44-x5x7-24c4 | Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 11 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
Tue, 10 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Mon, 09 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 09 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue. | |
| Title | Apache Airflow: Airflow externalLogUrl Permission Bypass | |
| Weaknesses | CWE-648 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-02-09T17:18:51.694Z
Reserved: 2026-01-13T14:15:57.516Z
Link: CVE-2026-22922
Updated: 2026-02-09T17:18:51.694Z
Status : Analyzed
Published: 2026-02-09T11:16:13.187
Modified: 2026-02-11T18:30:44.510
Link: CVE-2026-22922
No data.
OpenCVE Enrichment
Updated: 2026-02-10T11:06:54Z
Github GHSA