oss-security·11d agoCVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated#apache-airflow#authentication-bypass#authentikCVE-2026-86466 3 sources1
oss-security·11d agoCVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access#access-control#account-deactivation#apache-airflowCVE-2026-82310
oss-security·18d agoCVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass#apache-airflow#authentication-bypass#azure-adCVE-2026-75156