Description
Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the user it names, because the audience claim is never checked. Affects deployments using the FAB auth manager with Authentik OAuth where the same Authentik instance also serves other applications; the attacker needs a valid token for any of those other applications, not for Airflow.

CVE-2026-75156 corrected the same missing validation on the Azure AD path in this file; the Authentik path was left unchanged and is fixed here. Deployments that applied the CVE-2026-75156 fix and use Authentik must also upgrade for this one.

Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: unauthorized authentication bypass
Action: Apply Patch
AI Analysis

Impact

Apache Airflow FAB provider allows an attacker to forge an id_token that was issued for a different client application by a shared Authentik identity provider. The provider does not check the issuer or audience claims of the token it receives, so the token is accepted and the bearer is authenticated as the user specified in the token. This flaw permits unauthorized authentication to Airflow, enabling an attacker with a valid token for any other application served by the same Authentik instance to gain access to the Airflow deployment, potentially exposing or manipulating workflows and data.

Affected Systems

Deployments that use the Apache Airflow FAB provider with the Authentik OAuth path are affected. The issue is present on installations where the same Authentik identity provider serves multiple applications, and an attacker holds a token for one of those other applications. Deployments that applied the CVE-2026-75156 fix but still use Authentik are still impacted and must upgrade to version 3.9.0 or later.

Risk and Exploitability

The vulnerability is exploitable through the standard OAuth flow; an attacker can submit a counterfeit id_token to the Airflow authentication endpoint. The CVSS score of 8.1 indicates a high severity, and the EPSS score of < 1% together with the fact that the vulnerability is not listed in CISA KEV point to a low probability of exploitation. However, the potential impact is significant because it allows arbitrary authentication. The flaw exists because the code path never checks the audience claim, meaning that clients can be impersonated across applications served by the same Authentik provider.

Generated by OpenCVE AI on September 18, 2026 at 13:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade apache-airflow-providers-fab to version 3.9.0 or later, which validates issuer and audience in the Authentik OAuth path.
  • Check the Apache Airflow provider repository and project mailing lists for security advisories and additional vulnerability updates.
  • Confirm that your Airflow deployment does not expose the Authentik authentication endpoint to untrusted networks.

Generated by OpenCVE AI on September 18, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache apache-airflow-providers-fab
CPEs cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*
Vendors & Products Apache apache-airflow-providers-fab

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow Fab Provider
Vendors & Products Apache
Apache airflow Fab Provider

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000


Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the user it names, because the audience claim is never checked. Affects deployments using the FAB auth manager with Authentik OAuth where the same Authentik instance also serves other applications; the attacker needs a valid token for any of those other applications, not for Airflow. CVE-2026-75156 corrected the same missing validation on the Azure AD path in this file; the Authentik path was left unchanged and is fixed here. Deployments that applied the CVE-2026-75156 fix and use Authentik must also upgrade for this one. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.
Title Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
Weaknesses CWE-346
References

Subscriptions

Apache Airflow Fab Provider Apache-airflow-providers-fab
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-17T19:21:08.487Z

Reserved: 2026-09-07T14:27:21.954Z

Link: CVE-2026-86466

cve-icon Vulnrichment

Updated: 2026-09-17T19:21:02.020Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T10:16:54.837

Modified: 2026-09-18T14:29:43.570

Link: CVE-2026-86466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:30:09Z

Weaknesses