Insufficient Validation in Apache Airflow FAB Provider for Azure AD OAuth Logins
CVE-2026-75156
9.1CRITICAL
What is CVE-2026-75156?
The Apache Airflow FAB provider in versions 3.7.3 through 3.8.0 contains a vulnerability that fails to validate the issuer and audience of Azure AD id_tokens during OAuth login. This oversight allows an attacker to exploit any Azure tenant to generate a token that bypasses the signature verification process, granting unauthorized access to the Airflow UI. Even if the fix for a related vulnerability (CVE-2026-59243) has been applied, operators must upgrade to version 3.8.1 or later to ensure proper security measures are implemented.
Affected Version(s)
Apache Airflow FAB provider 3.7.3 < 3.8.1
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Roberto Nunes
NEO AI Engineer (@neo-ai-engineer, ProjectDiscovery)
Jarek Potiuk