ZeroHour
oss-securitypublished ()ingested

CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access

mediumVulnerabilityimportance 30CVE-2026-82310
AI summary · glm-5.3

Apache Airflow FAB provider 2.0.0-3.8.x lets deactivated users keep unexpired Core API JWTs and mint replacements indefinitely.

CVE-2026-82310 affects apache-airflow-providers-fab versions 2.0.0 before 3.9.0. Deactivating a user account does not stop tokens issued before deactivation. While password authentication correctly rejects the disabled account, the Core API continues to accept an existing unexpired token naming it and lets that token mint a replacement. Severity is rated moderate.

  • Affects apache-airflow-providers-fab 2.0.0 before 3.9.0
  • Deactivated accounts keep working via pre-existing JWTs
  • Core API lets old tokens mint replacement tokens
  • Password auth correctly rejects disabled accounts, JWT auth does not

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82310

NVD description · AI analysis pending
Full article

Posted by Vincent Beck on Sep 15 Severity: moderate Affected versions: - Apache Airflow FAB provider (apache-airflow-providers-fab) 2.0.0 before 3.9.0 Description: Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the...

This source does not provide full text. Read it at seclists.org.