Insufficient Validation in Apache Airflow FAB Provider for Azure AD OAuth Logins
CVE-2026-75156
Currently unrated
What is CVE-2026-75156?
The Apache Airflow FAB provider in versions 3.7.3 through 3.8.0 contains a vulnerability that fails to validate the issuer and audience of Azure AD id_tokens during OAuth login. This oversight allows an attacker to exploit any Azure tenant to generate a token that bypasses the signature verification process, granting unauthorized access to the Airflow UI. Even if the fix for a related vulnerability (CVE-2026-59243) has been applied, operators must upgrade to version 3.8.1 or later to ensure proper security measures are implemented.
Affected Version(s)
Apache Airflow FAB provider 3.7.3 < 3.8.1