PT-2026-93421 · Apache Airflow · Apache Airflow Fab Provider

·

CVE-2026-86466

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-fab versions prior to 3.9.0
Description The Authentik OAuth path in the FAB auth manager fails to validate the issuer or audience claims of the accepted id token. This allows an attacker who possesses a valid token minted by the same Authentik identity provider for a different client application to present it to Airflow and be authenticated as the specified user, as the audience claim is not verified.
Recommendations Upgrade to version 3.9.0 or later.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-RR24550
CVE-2026-86466

Affected Products

Apache Airflow Fab Provider