Token Authentication Flaw in Apache Airflow FAB Provider Affects User Account Deactivation
CVE-2026-82310

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-82310?

A vulnerability in the Apache Airflow FAB provider permits issued tokens to retain access post-account deactivation. When an administrator deactivates a user account, the system correctly restricts password authentication but fails to invalidate existing tokens linked to that account. This oversight allows unauthorized role-scoped access even after the account is supposedly disabled. Affected deployments using Airflow 3 with the FAB auth manager and Core API token authentication must be vigilant, as this vulnerability allows deactivated users to continue utilizing their old credentials, posing a significant security risk. Users are urged to upgrade to version 3.9.0 or higher to mitigate this risk.

Affected Version(s)

Apache Airflow FAB provider 2.0.0 < 3.9.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mayank Jangid (OpenSec)
Jarek Potiuk
.