Naar hoofdinhoud

CVE-2026-86466

8.1 HIGHEPSS 0.14%
  1. Gepubliceerd16 sep 2026

Beschrijving

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the user it names, because the audience claim is never checked. Affects deployments using the FAB auth manager with Authentik OAuth where the same Authentik instance also serves other applications; the attacker needs a valid token for any of those other applications, not for Airflow. CVE-2026-75156 corrected the same missing validation on the Azure AD path in this file; the Authentik path was left unchanged and is fixed here. Deployments that applied the CVE-2026-75156 fix and use Authentik must also upgrade for this one. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which fixes the issue.

CVSS 3.1-ontleding

Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Getroffen producten

Apache Apache-Airflow-Providers-Fab< 3.9.0

Veelgestelde vragen

Wordt CVE-2026-86466 actief misbruikt?

CVE-2026-86466 staat niet in de CISA KEV-catalogus. De EPSS-exploitkans is 0.14%.

Hoe ernstig is CVE-2026-86466?

CVE-2026-86466 heeft een CVSS 3.1-basisscore van 8.1, beoordeeld als high. EPSS schat een exploitkans van 0.14%.

Welke producten zijn getroffen door CVE-2026-86466?

Getroffen producten zijn onder meer Apache Apache-Airflow-Providers-Fab.

Hoe verhelp ik CVE-2026-86466?

Werk getroffen software bij naar een opgeloste versie, bijvoorbeeld Apache Apache-Airflow-Providers-Fab 3.9.0 of later, en controleer daarna dat er geen getroffen versies meer in uw inventaris staan.

Hoe Secuno hiermee omgaat

Secuno correleert kwetsbaarheden zoals CVE-2026-86466 dagelijks tegen de werkelijke software-inventaris op elk beheerd apparaat. In plaats van een statische ernst wordt elke match in context gescoord: exploitbeschikbaarheid, EPSS, de blootstelling van het asset en bedrijfskriticiteit bepalen de prioriteit. Als een getroffen versie ergens in uw portfolio aanwezig is, verschijnt die automatisch met een geprioriteerd hersteltraject.

Data uit de NVD, CISA KEV-catalogus en FIRST EPSS. CVSS 3.1-basisscore getoond indien beschikbaar.