CRITICAL🇵🇱 Wersja polska

CVE-2026-59243

CVSS 9.8v3.1pub. 2026-07-29upd. 2026-08-05

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Airflow Providers Fab

    APP
    Apache
    < 3.7.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-42447CRITICAL9.8PL ✓same product

Apache Airflow Providers FAB — nieprawidłowe wygasanie sesji (CWE-613)

CVE-2026-59245HIGH8.1PL ✓same product

Apache Airflow FAB: privilege escalation przez kolizję nazwy DAG 'DAGs'

CVE-2024-45033HIGH8.1same product

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airfl...

CVE-2026-46745MEDIUM5.3same product

Apache Airflow FAB Auth Manager zawiera podatność LDAP filter injection (CWE-90), która pozwala nieuwierzyteln...

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych