ZeroHour
Product

Apache Airflow

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass

Apache Airflow FAB provider flaw (CVE-2026-75156) lets attackers bypass Azure AD OAuth token validation via unvalidated issuer and audience claims.

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD id_tokens during OAuth login, enabling cross-tenant authentication bypass. The issue affects deployments where the FAB auth manager is configured with Azure AD as an OAuth provider. A fix is available in version 3.8.1. Severity is rated moderate.

oss-security · 8d agoVulnerabilityCVE-2026-75156

Related CVEs

  • Cross-tenant authentication bypass in Apache Airflow FAB provider
    CVE-2026-75156 is an origin-validation flaw (CWE-346) in the Apache Airflow FAB provider, which does not validate the issuer or audience of Azure AD id_tokens during OAuth login. It is triggered when the FAB auth manager is configured with Azure AD as the OAuth provider: because signing keys are fetched from Microsoft's multi-tenant JWKS endpoint, an id_token minted in any Azure tenant — including one the attacker registers — passes signature verification, and the username and role assignments in that attacker-controlled token are accepted. An attacker with no prior access to the deployment can therefore authenticate to the Airflow UI as an arbitrarily chosen user/role, gaining whatever access those assignments grant. Affected versions are 3.7.3 through 3.8.0, including every release containing the earlier CVE-2026-59243 signature-verification fix, so operators who already patched for that issue remain exposed and must upgrade again. No public proof-of-concept or known exploitation has been reported (EPSS 0.2%, not in CISA KEV).
    · Apache Airflow FAB provider (apache-airflow-providers-fab) — deployments using the FAB auth manager with Azure AD as OAuth prov 3.7.3 through 3.8.0 (fixed in 3.8.1)large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.