PT-2026-93401 · Apache · Apache Airflow Fab Provider
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
apache-airflow-providers-fab versions prior to 3.9.0
Description
Resetting a user password fails to delete existing database-backed sessions when using the FAB auth manager with
[fab] session backend=database. This occurs because the cleanup process compares a string identifier stored by Flask-Login in the session against the user's integer database identifier, resulting in a mismatch that prevents session removal. Consequently, an attacker possessing a victim's session cookie maintains access even after a password reset. Additionally, a similar issue exists via the Admin user-edit endpoint.Recommendations
Upgrade to version 3.9.0 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Fab Provider