CVE-2026-59243
apache-airflow-providers-fab: Improper Verification of Cryptographic Signature (CVE-2026-59243)
Beschreibung
Der Auth-Manager von FAB setzte beim Dekodieren des ID-Tokens die Standardoption `verify_signature=False`, wodurch ein Angreifer in der Lage war, ein gefälschtes oder nicht signiertes (`alg:none`) ID-Token an den OAuth-Rückruf zu übermitteln und so die Authentifizierung umgehen sowie sich als beliebiger Benutzer anmelden, einschließlich eines mit der Admin-Rolle (CWE-347). Betroffen sind Bereitstellungen, bei denen der FAB Auth-Manager unter Verwendung des Azure AD OAuth-Anmeldepfads in der Standardkonfiguration läuft; der Authentik-Pfad setzte bereits standardmäßig auf `True`. Dieses Problem betrifft `apache-airflow-providers-fab` vor Version 3.7.3. Benutzer werden dazu geraten, auf `apache-airflow-providers-fab` Version 3.7.3 zu aktualisieren, die standardmäßig `verify_signature=True` setzt.
Metriken
Weakness-Klassen (CWE)
CWE-347Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Initial Analysis2026-08-05 18:37 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:* versions up to (excluding) 3.7.3
- Reference Type: Apache Software Foundation: https://github.com/apache/airflow/pull/69374 Types: Patch
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl Types: Mailing List, Vendor Advisory
- Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/07/28/10 Types: Mailing List, Third Party Advisory
- New CVE Received2026-07-29 10:16 UTC· security@apache.org
- Affected: Apache Airflow FAB provider
- Description: The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
- CWE: CWE-347
- Reference: https://github.com/apache/airflow/pull/69374
- CVE Modified2026-07-29 10:16 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/07/28/10
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
apache
apache-airflow-providers-fab3.7.3