{"schema_version": "1.6.1", "id": "CVE-2026-59245", "summary": "FAB auth manager: a DAG named \"DAGs\" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)", "details": "In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "0"}, {"fixed": "3.7.2"}]}]}], "references": [{"type": "WEB", "url": "https://github.com/apache/airflow/pull/69106"}, {"type": "WEB", "url": "https://lists.apache.org/thread/70f37q3mwov1vm3zolrfxlzds278c78h"}]}