CVE-2026-86462(apache / apache-airflow-providers-fab)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. Affects deployments using the FAB auth manager with database-backed sessions; an administrator (or the user themselves) performing a routine password change is the trigger, and no attacker interaction with the endpoint is needed. This is a second, independent route to the outcome addressed by CVE-2026-82311, which corrected an identifier comparison in the session-invalidation helper. That fix does not repair this endpoint, because the PATCH path never calls the helper at all. Deployments that applied the CVE-2026-82311 fix must also upgrade for this one. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache-airflow-providers-fab

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
apache-airflow-providers-fab

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-23: 109-23
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ryx@PadhiyarRushi

    Airflow FAB password reset fails to kill existing sessions. CVE-2026-82311 (and related CVE-2026-86462): password change does not invalidate database-backed sessions because of a string/int _user_id comparison bug. Attacker with a stolen cookie keeps access after reset. Fixed in apache-airflow-providers-fab 3.9.0. https://cve.circl.lu/vuln/cve-2026-82311 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #CloudSecurity

    00013297
    911 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheapache-airflow-providers-fab---

Explore more