Description
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. Affects deployments using the FAB auth manager with database-backed sessions; an administrator (or the user themselves) performing a routine password change is the trigger, and no attacker interaction with the endpoint is needed.

This is a second, independent route to the outcome addressed by CVE-2026-82311, which corrected an identifier comparison in the session-invalidation helper. That fix does not repair this endpoint, because the PATCH path never calls the helper at all. Deployments that applied the CVE-2026-82311 fix must also upgrade for this one.

Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Session persistence after password reset allowing continued access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the Admin password‑edit PATCH endpoint of the Apache Airflow FAB provider, where changing a user’s password does not invalidate existing database‑backed sessions tied to that user. Because session cookies remain valid, any entity that already possesses a victim’s session cookie can continue to act with the victim’s credentials even after the password change. This flaw represents an improper session validation weakness (CWE‑613) and undermines the security guarantee that a password change revokes all active sessions.

Affected Systems

Impact is limited to deployments using the FAB authentication manager with database‑backed sessions. The flaw applies to all versions of apache-airflow-providers-fab prior to the release of version 3.9.0; the patch introduces session‑invalidation during password changes.

Risk and Exploitability

The vulnerability can be exploited only if an attacker already has a session cookie for the target. Because the EPSS score is < 1% and the CVSS score is 9.1, and the flaw is not listed in CISA’s KEV catalog, the exploitation that an attacker who already hijacked a session can persist indefinitely indicates a high potential impact. The network attack vector is indirect, depending on prior session compromise.

Generated by OpenCVE AI on September 18, 2026 at 12:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade apache-airflow-providers-fab to version 3.9.0 or later, which adds session invalidation on password change.
  • If an upgrade cannot be performed immediately, disable database‑backed session storage or switch to a different session backend to prevent session persistence.
  • After applying the patch or changing session backend, audit existing sessions and force log‑out for all users, especially those who recently changed passwords, to ensure no stale sessions remain.

Generated by OpenCVE AI on September 18, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache apache-airflow-providers-fab
CPEs cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*
Vendors & Products Apache apache-airflow-providers-fab

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow Fab Provider
Vendors & Products Apache
Apache airflow Fab Provider

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000


Wed, 16 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. Affects deployments using the FAB auth manager with database-backed sessions; an administrator (or the user themselves) performing a routine password change is the trigger, and no attacker interaction with the endpoint is needed. This is a second, independent route to the outcome addressed by CVE-2026-82311, which corrected an identifier comparison in the session-invalidation helper. That fix does not repair this endpoint, because the PATCH path never calls the helper at all. Deployments that applied the CVE-2026-82311 fix must also upgrade for this one. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.
Title Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
Weaknesses CWE-613
References

Subscriptions

Apache Airflow Fab Provider Apache-airflow-providers-fab
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-17T19:24:52.871Z

Reserved: 2026-09-07T14:15:13.978Z

Link: CVE-2026-86462

cve-icon Vulnrichment

Updated: 2026-09-17T19:24:43.831Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T09:17:07.090

Modified: 2026-09-18T14:29:11.393

Link: CVE-2026-86462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T12:15:06Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration