Intel

AIKIDO-2026-996543

apache-airflow-providers-fab is vulnerable to Insufficient Session Expiration

Insufficient Session ExpirationCVE-2026-86462 Published 2 days ago

91

Critical Risk

This Affects:

PYTHONapache-airflow-providers-fab
3.2.0 - 3.8.1
Fixed in 3.9.0
Are you affected? Scan for Free

TL;DR

The FAB provider's Admin user-edit PATCH endpoint lets an administrator change another user's password without invalidating that user's existing active sessions. A user whose password was changed this way keeps using their prior session token as if nothing happened. This lets a compromised or rotated account remain reachable through a session that a password change was meant to kill. The fix invalidates existing sessions when an admin changes a user's password through this endpoint.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and rely on an admin-initiated password change to cut off a compromised or departing user's active session.

Background info

apache-airflow-providers-fab is vulnerable to Insufficient Session Expiration in versions 3.2.0 - 3.8.1.

How to fix this

Upgrade the apache-airflow-providers-fab library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform