Insufficient Validation in Apache Airflow FAB Provider for Azure AD OAuth Logins
CVE-2026-75156

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 September 2026

What is CVE-2026-75156?

The Apache Airflow FAB provider in versions 3.7.3 through 3.8.0 contains a vulnerability that fails to validate the issuer and audience of Azure AD id_tokens during OAuth login. This oversight allows an attacker to exploit any Azure tenant to generate a token that bypasses the signature verification process, granting unauthorized access to the Airflow UI. Even if the fix for a related vulnerability (CVE-2026-59243) has been applied, operators must upgrade to version 3.8.1 or later to ensure proper security measures are implemented.

Affected Version(s)

Apache Airflow FAB provider 3.7.3 < 3.8.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Roberto Nunes
NEO AI Engineer (@neo-ai-engineer, ProjectDiscovery)
Jarek Potiuk
.