Session Management Flaw in Apache Airflow Core API
CVE-2026-86473

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 September 2026

What is CVE-2026-86473?

A session management flaw in the Core API of Apache Airflow allows an attacker to exploit the logout endpoint. When a client logs out using an Authorization bearer header, the logout response does not invalidate the session token. This behavior can allow attackers who have previously acquired a valid token to continue accessing the system, even after the legitimate user has logged out. The vulnerability specifically affects API clients that utilize bearer tokens rather than browser session cookies, making it critical for users to upgrade to Apache Airflow version 3.3.2 or later to ensure proper session invalidation.

Affected Version(s)

Apache Airflow 3.0.0 < 3.3.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

OpenSec Intelligence
Jarek Potiuk
.