CVE-2026-46745Disclosure(apache / apache-airflow-providers-fab)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache-airflow-providers-fab

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
apache-airflow-providers-fab

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-05-26: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 105-2405-2505-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-241
General1
2026-05-251
Disclosure1
2026-05-261
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Airflow CVE-2026-45361: Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default) https://www.openwall.com/lists/oss-security/2026/05/24/9 CVE-2026-46745: FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap https://www.openwall.com/lists/oss-security/2026/05/24/10

    Post summary

    The post announces two new Apache Airflow CVEs, detailing missing SSH host key verification and an LDAP filter injection flaw, but provides no PoC, exploit, or mitigation information.

    01050592
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46745 Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass … https://www.cve.org/CVERecord?id=CVE-2026-46745

    Post summary

    A disclosure of an LDAP filter injection flaw in Apache Airflow’s FAB Auth Manager that allows unauthenticated attackers to exfiltrate directory data or bypass access, with no PoC, exploit, or patch details provided.

    00000211
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-46745 CVE-2026-46745 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-46745

    Post summary

    The provided text only lists the CVE ID with a link to a vulnerability database, offering no substantive details or claims about exploitation, patches, or technical specifics.

    0000066
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheapache-airflow-providers-fab---

Explore more