PT-2026-24054 · Apache · Apache Airflow

·

CVE-2026-25604

·

Published

2026-03-09

·

Updated

2026-07-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 9.22.0
Description The AWS Auth Manager in Apache Airflow did not verify the origin of SAML authentication against the actual instance URL, relying instead on information provided by the client. This allowed for potential access to different instances with varying access controls by reusing SAML responses from other instances.
Recommendations Upgrade to version 9.22.0 of the AWS Auth Manager provider.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25604
ECHO-909D-8F32-2A00
GHSA-RV5F-CCPM-XJJ4
PYSEC-2026-2363

Affected Products

Apache Airflow