PT-2026-96120 · Apache · Apache Airflow

·

CVE-2026-82355

·

Published

2026-09-21

·

Updated

2026-09-26

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.3.0 through 3.3.1
Description An issue exists in the Airflow core API where the system incorrectly prioritizes a session cookie over an explicit Authorization: Bearer token when both are present in a request. This causes the system to resolve the caller based on the cookie and ignore the bearer token, leading to principal confusion and misattributed audit records. Exploitation requires an attacker to place a valid session cookie into the victim's browser or client, which can occur via cookie tossing from a sibling subdomain, cross-site scripting in a separate application sharing a parent domain, or through a shared workstation. This is primarily a risk for deployments hosting the Airflow UI on a domain shared with other applications.
Recommendations Upgrade Apache Airflow versions 3.3.0 through 3.3.1 to version 3.3.2 or later.

Exploit

Fix

LPE

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-82355
CVE-2026-82355
PYSEC-2026-3989

Affected Products

Apache Airflow