Apache Airflow FAB provider
5 known vulnerabilities in Apache Airflow FAB provider, 3 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-86466 CVSS 8.1 high Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the…
- CVE-2026-82310 CVSS 7.2 high Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password…
- CVE-2026-86462 CVSS 9.1 critical Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's…
- CVE-2026-82311 CVSS 9.8 critical Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented…
- CVE-2026-75156 CVSS 9.1 critical Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth…