CVE-2026-86473
Last modified
CVE-2026-86473 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the victim has logged out and believes the session ended; the default token lifetime is 24 hours and is configurable. Affects API clients that authenticate with a bearer token rather than the browser session cookie. The attacker must already possess a copy of a valid token; obtaining one is outside the scope of this issue, and no privileges beyond the victim's own are gained. Users of apache-airflow are recommended to upgrade to apache-airflow version 3.3.2 or later, which fixes the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | >= 3.0.0, < 3.3.2 |
References
- https://github.com/apache/airflow/pull/72649Issue Tracking, Vendor Advisory
- https://lists.apache.org/thread/k9z1p0q1ng8m68nlnv9d1fqzscrfm7vrMailing List, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2026/09/21/5Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-86473?
How severe is CVE-2026-86473?
How do I fix CVE-2026-86473?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86464In the current development version of Eclipse aeriOS, for wh…9.9
- CVE-2026-86465Apache Airflow Akeyless provider: the Akeyless secrets backe…6.5
- CVE-2026-86466Apache Airflow FAB provider: the Authentik OAuth path in the…8.1
- CVE-2026-86469A flaw was found in GLib2. When g_file_replace() is used wit…5.3
- CVE-2026-8647Crypt::ScryptKDF versions through 0.010 for Perl uses insecu…4.8
- CVE-2026-86472fast-uri is a dependency-free RFC 3986 URI parser for Node.j…4.8
- CVE-2026-86474The lack of TLS certificate validation when downloading firm…7.7
- CVE-2026-86475The Appointment Hour Booking WordPress plugin before 1.5.95 …5.3
- CVE-2026-86477Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-86478In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 im…9.8
- CVE-2026-86479In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2…8.1
- CVE-2026-86480In JetBrains Hub before 2026.2.52442 an unauthenticated atta…9.8
Are you affected by CVE-2026-86473?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
