CVE-2026-86462
Last modified
CVE-2026-86462 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. Affects deployments using the FAB auth manager with database-backed sessions; an administrator (or the user themselves) performing a routine password change is the trigger, and no attacker interaction with the endpoint is needed. This is a second, independent route to the outcome addressed by CVE-2026-82311, which corrected an identifier comparison in the session-invalidation helper. That fix does not repair this endpoint, because the PATCH path never calls the helper at all. Deployments that applied the CVE-2026-82311 fix must also upgrade for this one. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Apache-Airflow-Providers-Fab | >= 3.2.0, < 3.9.0 |
References
- https://github.com/apache/airflow/pull/72657Patch, Vendor Advisory
- https://lists.apache.org/thread/7sr4sggfv5fhhl3qgphcq0rlhg81do1sMailing List, Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-82311US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-86462?
How severe is CVE-2026-86462?
How do I fix CVE-2026-86462?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86448The LearnPress WordPress plugin before 4.4.7 does not perfo…3.7
- CVE-2026-86449The LearnPress WordPress plugin before 4.4.7 does not check…5.3
- CVE-2026-86451Affected versions of MISP allow authenticated users to retri…4.3
- CVE-2026-86452Affected versions of MISP permit unauthenticated or weakly c…7.5
- CVE-2026-8646IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphe…9.1
- CVE-2026-86460Cypher injection vulnerability in the Neo4j persistence laye…9.8
- CVE-2026-86464In the current development version of Eclipse aeriOS, for wh…9.9
- CVE-2026-86465Apache Airflow Akeyless provider: the Akeyless secrets backe…6.5
- CVE-2026-86466Apache Airflow FAB provider: the Authentik OAuth path in the…8.1
- CVE-2026-86469A flaw was found in GLib2. When g_file_replace() is used wit…5.3
- CVE-2026-8647Crypt::ScryptKDF versions through 0.010 for Perl uses insecu…4.8
- CVE-2026-86472fast-uri is a dependency-free RFC 3986 URI parser for Node.j…4.8
Are you affected by CVE-2026-86462?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
