PT-2026-45379 · Apache · Apache Airflow

Bernardo Curi

+1

·

Published

2026-06-01

·

Updated

2026-06-05

·

CVE-2026-48726

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.2.2
Description A bug in the authentication manager logout handling allows previously issued JSON Web Tokens (JWT) to remain valid after a user logs out via the user interface. In deployments configured with FabAuthManager or KeycloakAuthManager, the logout flow fails to trigger the revoke token() function, meaning the API server continues to accept the token until it expires naturally. This allows an attacker possessing a JWT from a logged-out session to perform authenticated API calls as that user.
Recommendations Update to version 3.2.2 or later.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-48726
CVE-2026-48726
PYSEC-2026-187

Affected Products

Apache Airflow