CVE-2026-59243
apache-airflow-providers-fab: Improper Verification of Cryptographic Signature (CVE-2026-59243)
Affected
- apache/apache-airflow-providers-fab
lt *..3.7.3
Description
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
3.7.3fixed from 3.7.3Metrics
Show all metrics
Weakness classes (CWE)
CWE-347Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-16 15:17 UTC· security@apache.org
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/59xxx/CVE-2026-59243.json">CVE-2026-59243</a>
- Reference: https://github.com/apache/airflow/pull/69374
- Reference: https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl
- Reference: https://github.com/apache/airflow/pull/69374
- CVE Modified2026-09-16 15:17 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/07/28/10
- Reference: http://www.openwall.com/lists/oss-security/2026/07/28/10
- Reference Type: http://www.openwall.com/lists/oss-security/2026/07/28/10 Types: Mailing List, Third Party Advisory
- Initial Analysis2026-08-05 18:37 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:* versions up to (excluding) 3.7.3
- Reference Type: Apache Software Foundation: https://github.com/apache/airflow/pull/69374 Types: Patch
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl Types: Mailing List, Vendor Advisory
- Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/07/28/10 Types: Mailing List, Third Party Advisory
- New CVE Received2026-07-29 10:16 UTC· security@apache.org
- Affected: Apache Airflow FAB provider
- Description: The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
- CWE: CWE-347
- Reference: https://github.com/apache/airflow/pull/69374
- CVE Modified2026-07-29 10:16 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/07/28/10