CVE-2026-86466
- EPSS 0.14%
- Veröffentlicht 16.09.2026 09:12:51
- Zuletzt bearbeitet 18.09.2026 14:29:43
Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different cli...
CVE-2026-82310
- EPSS 0.25%
- Veröffentlicht 16.09.2026 09:09:07
- Zuletzt bearbeitet 18.09.2026 14:28:10
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired toke...
CVE-2026-86462
- EPSS 0.2%
- Veröffentlicht 16.09.2026 09:05:42
- Zuletzt bearbeitet 18.09.2026 14:29:11
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full acces...
CVE-2026-82311
- EPSS 0.2%
- Veröffentlicht 16.09.2026 09:00:38
- Zuletzt bearbeitet 18.09.2026 14:28:43
Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against th...
CVE-2026-75156
- EPSS 0.18%
- Veröffentlicht 08.09.2026 16:47:48
- Zuletzt bearbeitet 18.09.2026 14:25:21
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Beca...
CVE-2026-59243
- EPSS 0.68%
- Veröffentlicht 29.07.2026 08:35:37
- Zuletzt bearbeitet 16.09.2026 15:17:39
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an ar...
CVE-2026-59245
- EPSS 0.36%
- Veröffentlicht 13.07.2026 15:05:21
- Zuletzt bearbeitet 16.09.2026 15:17:39
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the globa...
CVE-2026-46745
- EPSS 0.58%
- Veröffentlicht 25.05.2026 10:41:16
- Zuletzt bearbeitet 23.07.2026 17:10:00
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate...
CVE-2024-45033
- EPSS 0.95%
- Veröffentlicht 08.01.2025 09:15:07
- Zuletzt bearbeitet 03.06.2025 21:11:55
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leadin...
CVE-2024-42447
- EPSS 0.93%
- Veröffentlicht 05.08.2024 08:15:56
- Zuletzt bearbeitet 19.03.2025 15:15:49
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user f...