PT-2026-93401 · Apache · Apache Airflow Fab Provider

·

CVE-2026-82311

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-fab versions prior to 3.9.0
Description Resetting a user password fails to delete existing database-backed sessions when using the FAB auth manager with [fab] session backend=database. This occurs because the cleanup process compares a string identifier stored by Flask-Login in the session against the user's integer database identifier, resulting in a mismatch that prevents session removal. Consequently, an attacker possessing a victim's session cookie maintains access even after a password reset. Additionally, a similar issue exists via the Admin user-edit endpoint.
Recommendations Upgrade to version 3.9.0 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-GK10237
CVE-2026-82311

Affected Products

Apache Airflow Fab Provider