๐Ÿ” CVE Alert

CVE-2026-82311

UNKNOWN 0.0

Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches and no session is removed. An attacker who already holds a copy of the victim's session cookie keeps access as that user after the password change, so the reset does not evict them. Affects deployments using the FAB auth manager with `[fab] session_backend=database`. The trigger is an administrator (or the user) running the supported password-reset command as a containment action after a session cookie has been compromised; the secure-cookie backend is out of scope, as it documents that it cannot centrally delete sessions. apache-airflow-providers-fab 3.9.0 also fixes CVE-2026-86462, a second, independent route to the same outcome via the Admin user-edit endpoint; a single upgrade closes both. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which compares the identifiers consistently.

CWE CWE-613
Vendor apache software foundation
Product apache airflow fab provider
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow fab provider

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache airflow fab provider are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow FAB provider
2.4.2 < 3.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/72198 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-86462 lists.apache.org: https://lists.apache.org/thread/mmplwl93shy615shkpp9p4fzyjvr4yqw

Credits

Mayank Jangid (OpenSec) Jarek Potiuk