ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 3 sources: “Apache Airflow FAB provider 3.9.0 fixes three moderate CVEs: broken session invalidation on password reset and missing Authentik id_token issuer/audience validation” — merged summary and timeline →

CVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions

mediumVulnerabilityimportance 30CVE-2026-86462
AI summary · glm-5.3

Apache Airflow FAB provider 3.2.0-3.8.x password changes do not invalidate database-backed sessions, letting stolen session cookies survive a password reset.

CVE-2026-86462 affects apache-airflow-providers-fab versions 3.2.0 before 3.9.0. Changing a user's password via the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie retains full access as that user after the password change. Severity is rated moderate.

  • Affects apache-airflow-providers-fab 3.2.0 before 3.9.0
  • Admin PATCH password change leaves DB sessions valid
  • Stolen session cookies survive password reset
  • Fixed in FAB provider 3.9.0

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-86462

NVD description · AI analysis pending
Full article

Posted by Vincent Beck on Sep 15 Severity: moderate Affected versions: - Apache Airflow FAB provider (apache-airflow-providers-fab) 3.2.0 before 3.9.0 Description: Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so...

This source does not provide full text. Read it at seclists.org.