Token Authentication Flaw in Apache Airflow FAB Provider Affects User Account Deactivation
CVE-2026-82310
Currently unrated
What is CVE-2026-82310?
A vulnerability in the Apache Airflow FAB provider permits issued tokens to retain access post-account deactivation. When an administrator deactivates a user account, the system correctly restricts password authentication but fails to invalidate existing tokens linked to that account. This oversight allows unauthorized role-scoped access even after the account is supposedly disabled. Affected deployments using Airflow 3 with the FAB auth manager and Core API token authentication must be vigilant, as this vulnerability allows deactivated users to continue utilizing their old credentials, posing a significant security risk. Users are urged to upgrade to version 3.9.0 or higher to mitigate this risk.
Affected Version(s)
Apache Airflow FAB provider 2.0.0 < 3.9.0