CVE-2026-82310
CVE-2026-82310: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityHigh7.2
High [CVE-2026-82310] Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation
CVE-2026-82310Source published Source updated
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the account keeps its role-scoped access indefinitely after an administrator has disabled it. The user replays their own legitimate credential; no signature forgery or privilege escalation is involved, and the access stays within the roles the account already held. Affects deployments using Airflow 3 with the FAB auth manager and Core API token authentication, where an administrator deactivates an account whose row remains in the database and whose previously issued token has not…
- Related products — impact not confirmed
- Apache Airflow FAB
- Source-reported affected versions
- Apache Airflow FAB provider 2.0.0 before 3.9.0
- Source-reported fixed versions
- 3.9.0
- Mitigation guidance
- Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which rejects tokens naming a deactivated account.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.