PT-2026-93416 · Apache Airflow · Apache Airflow Fab Provider

·

CVE-2026-82310

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-fab versions prior to 3.9.0
Description Deactivating a user account does not invalidate tokens issued to that account prior to the deactivation. While password authentication correctly rejects disabled accounts, the Core API continues to accept existing, unexpired tokens and allows them to mint replacements. This enables an account to maintain role-scoped access indefinitely after an administrator has disabled it by replaying legitimate credentials. This issue occurs in deployments using Airflow 3 with the FAB auth manager and Core API token authentication when an account is deactivated but its record remains in the database.
Recommendations Upgrade to version 3.9.0 or later.

Exploit

Fix

LPE

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-FC44731
CVE-2026-82310

Affected Products

Apache Airflow Fab Provider