PT-2026-93421 · Apache Airflow · Apache Airflow Fab Provider
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
apache-airflow-providers-fab versions prior to 3.9.0
Description
The Authentik OAuth path in the FAB auth manager fails to validate the issuer or audience claims of the accepted
id token. This allows an attacker who possesses a valid token minted by the same Authentik identity provider for a different client application to present it to Airflow and be authenticated as the specified user, as the audience claim is not verified.Recommendations
Upgrade to version 3.9.0 or later.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Fab Provider