CVE-2026-82310
Last modified
CVE-2026-82310 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the account keeps its role-scoped access indefinitely after an administrator has disabled it. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the account keeps its role-scoped access indefinitely after an administrator has disabled it. The user replays their own legitimate credential; no signature forgery or privilege escalation is involved, and the access stays within the roles the account already held. Affects deployments using Airflow 3 with the FAB auth manager and Core API token authentication, where an administrator deactivates an account whose row remains in the database and whose previously issued token has not expired. The trigger is administrative deactivation as a containment action, which silently fails to contain. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which rejects tokens naming a deactivated account.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Apache-Airflow-Providers-Fab | >= 2.0.0, < 3.9.0 |
References
- https://github.com/apache/airflow/pull/72199Patch, Vendor Advisory
- https://lists.apache.org/thread/85h9r50bmy8vgkgr5nyddryj1p5pxxy2Mailing List, Vendor Advisory
- https://lists.apache.org/thread/85h9r50bmy8vgkgr5nyddryj1p5pxxy2?users@airflow.apache.orgMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-82310?
How severe is CVE-2026-82310?
How do I fix CVE-2026-82310?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82302Incorrect Authorization (CWE-863) in Kibana can lead to unau…8.1
- CVE-2026-82304The Music Store WordPress plugin before 1.4.5 does not sani…8.6
- CVE-2026-82305The YITH WooCommerce Wishlist WordPress plugin before 4.18.1…5.3
- CVE-2026-82306StarRocks through 4.0.13 contains an information disclosure …6.5
- CVE-2026-82309Robots::Validate versions from 0.3.2 before 0.3.11 for Perl …4.3
- CVE-2026-8231A vulnerability has been found in CodeAstro Online Catering …6.3
- CVE-2026-82311Apache Airflow FAB provider: resetting a user's password doe…9.8
- CVE-2026-82312OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on…1.8
- CVE-2026-8232A vulnerability was found in Dotouch XproUPF 2.0.0-release-0…5.1
- CVE-2026-82324A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. …6.1
- CVE-2026-82325A use-after-free vulnerability in the OpenVPN ovpn-dco-win d…6.8
- CVE-2026-82327A flaw was found in libsolv, a dependency-resolution library…5.5
Are you affected by CVE-2026-82310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
