Description
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. Affects deployments using the FAB auth manager with database-backed sessions; an administrator (or the user themselves) performing a routine password change is the trigger, and no attacker interaction with the endpoint is needed.

This is a second, independent route to the outcome addressed by CVE-2026-82311, which corrected an identifier comparison in the session-invalidation helper. That fix does not repair this endpoint, because the PATCH path never calls the helper at all. Deployments that applied the CVE-2026-82311 fix must also upgrade for this one.

Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Session persistence after password reset allowing continued access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the Admin password‑edit PATCH endpoint of the Apache Airflow FAB provider, where changing a user’s password does not invalidate existing database‑backed sessions tied to that user. Because session cookies remain valid, any entity that already possesses a victim’s session cookie can continue to act with the victim’s credentials even after the password change. This flaw represents an improper session validation weakness (CWE‑613) and undermines the security guarantee that a password change revokes all active sessions.

Affected Systems

Impact is limited using the FAB authentication manager configured for database‑backed sessions. The flaw applies to all versions prior to the release of version 3.9.0, which introduced a session‑invalidation mechanism during password changes.

Risk and Exploitability

The vulnerability can be exploited only if an attacker already has a session cookie for the target vulnerable endpoint is required. Because the EPSS score is 0.00195 (less than 1%) and the flaw is not listed in CISA’s KEV catalog, the exploitation that an attacker who already hijacked a session can persist indefinitely indicates a high potential impact. The network attack vector is indirect, depending on prior session compromise. The severity is elevated by the fact that a routine password change—which is a normal administrative action—fails to enforce the expected isolation of authenticated sessions.

Generated by OpenCVE AI on September 16, 2026 at 14:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade apache-airflow-providers-fab to version 3.9.0 or later, which adds session invalidation on password change.
  • If an upgrade cannot be performed immediately, disable database‑backed session storage or switch to a different session backend to prevent session persistence.
  • After applying the patch or changing session backend, audit existing sessions and force log‑out for all users, especially those who recently changed passwords, to ensure no stale sessions remain.

Generated by OpenCVE AI on September 16, 2026 at 14:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:00:00 +0000


Wed, 16 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. Affects deployments using the FAB auth manager with database-backed sessions; an administrator (or the user themselves) performing a routine password change is the trigger, and no attacker interaction with the endpoint is needed. This is a second, independent route to the outcome addressed by CVE-2026-82311, which corrected an identifier comparison in the session-invalidation helper. That fix does not repair this endpoint, because the PATCH path never calls the helper at all. Deployments that applied the CVE-2026-82311 fix must also upgrade for this one. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.
Title Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
Weaknesses CWE-613
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-16T14:54:55.778Z

Reserved: 2026-09-07T14:15:13.978Z

Link: CVE-2026-86462

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T09:17:07.090

Modified: 2026-09-16T19:08:00.110

Link: CVE-2026-86462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:00:07Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration