CVE-2026-59243

apache-airflow-providers-fab: Improper Verification of Cryptographic Signature (CVE-2026-59243)

criticalPoCEPSS 0.6%

Affected

  • apache/apache-airflow-providers-fab lt *..3.7.3

Description

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

apacheapache-airflow-providers-fab
3.7.3fixed from 3.7.3

Metrics

9.8
Source: nvd-v3
49.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
PoC (publicly reported)
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-29 10:16 UTC
CWE-347

Weakness classes (CWE)

  • CWE-347Base

    Improper Verification of Cryptographic Signature

    The product does not verify, or incorrectly verifies, the cryptographic signature for data.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-16 15:17 UTC· security@apache.org
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/59xxx/CVE-2026-59243.json">CVE-2026-59243</a>
    • Reference: https://github.com/apache/airflow/pull/69374
    • Reference: https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl
    • Reference: https://github.com/apache/airflow/pull/69374
  2. CVE Modified2026-09-16 15:17 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/07/28/10
    • Reference: http://www.openwall.com/lists/oss-security/2026/07/28/10
    • Reference Type: http://www.openwall.com/lists/oss-security/2026/07/28/10 Types: Mailing List, Third Party Advisory
  3. Initial Analysis2026-08-05 18:37 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:* versions up to (excluding) 3.7.3
    • Reference Type: Apache Software Foundation: https://github.com/apache/airflow/pull/69374 Types: Patch
    • Reference Type: Apache Software Foundation: https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl Types: Mailing List, Vendor Advisory
    • Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/07/28/10 Types: Mailing List, Third Party Advisory
  4. New CVE Received2026-07-29 10:16 UTC· security@apache.org
    • Affected: Apache Airflow FAB provider
    • Description: The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
    • CWE: CWE-347
    • Reference: https://github.com/apache/airflow/pull/69374
  5. CVE Modified2026-07-29 10:16 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/07/28/10

Linked advisories