PT-2026-93416 · Apache Airflow · Apache Airflow Fab Provider
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
apache-airflow-providers-fab versions prior to 3.9.0
Description
Deactivating a user account does not invalidate tokens issued to that account prior to the deactivation. While password authentication correctly rejects disabled accounts, the Core API continues to accept existing, unexpired tokens and allows them to mint replacements. This enables an account to maintain role-scoped access indefinitely after an administrator has disabled it by replaying legitimate credentials. This issue occurs in deployments using Airflow 3 with the FAB auth manager and Core API token authentication when an account is deactivated but its record remains in the database.
Recommendations
Upgrade to version 3.9.0 or later.
Exploit
Fix
LPE
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Fab Provider