PT-2026-65767 · Apache · Apache Airflow Fab Provider
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The FAB auth manager's Azure AD OAuth login defaulted
verify signature=False when decoding the ID token, so an attacker able to present a forged or unsigned (alg:none) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to True. This issue affects apache-airflow-providers-fab before 3.7.3. Users are advised to upgrade to apache-airflow-providers-fab 3.7.3, which defaults verify signature=True.Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Fab Provider