{"id":"CVE-2026-82311","published":"2026-09-16T09:17:06.430","lastModified":"2026-09-18T14:28:43.283","description":"Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches and no session is removed. An attacker who already holds a copy of the victim's session cookie keeps access as that user after the password change, so the reset does not evict them.\n\nAffects deployments using the FAB auth manager with `[fab] session_backend=database`. The trigger is an administrator (or the user) running the supported password-reset command as a containment action after a session cookie has been compromised; the secure-cookie backend is out of scope, as it documents that it cannot centrally delete sessions.\n\napache-airflow-providers-fab 3.9.0 also fixes CVE-2026-86462, a second, independent route to the same outcome via the Admin user-edit endpoint; a single upgrade closes both.\n\nUsers of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which compares the identifiers consistently.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-613"],"vendors":["apache"],"products":["apache-airflow-providers-fab"],"references":[{"url":"https://github.com/apache/airflow/pull/72198","tags":["Patch","Vendor Advisory"]},{"url":"https://lists.apache.org/thread/mmplwl93shy615shkpp9p4fzyjvr4yqw","tags":["Mailing List","Vendor Advisory"]},{"url":"https://lists.apache.org/thread/mmplwl93shy615shkpp9p4fzyjvr4yqw?users@airflow.apache.org","tags":["Mailing List"]},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-86462","tags":["Third Party Advisory"]}],"exploitRefs":[{"url":"https://github.com/apache/airflow/pull/72198","tags":["Patch","Vendor Advisory"]}],"hasPoc":true,"ai":{"summary":"This flaw allows an attacker to maintain access to a user's account after their password is reset, due to improper session cleanup.","exploitability":"Exploitation is moderately hard as it requires the attacker to have a copy of the victim's session cookie and the ability to run the password-reset command.","blast_radius":"The impact is significant as it can lead to unauthorized access and data breaches in affected deployments.","remediation":"Upgrade to apache-airflow-providers-fab 3.9.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","airflow","session","password-reset"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:59:44.703Z"}}