← Back to search

CVE-2026-82311

9.8 CRITICALpublic exploit available

Published 2026-09-16 · Updated 2026-09-18

AI risk analysis

Summary
This flaw allows an attacker to maintain access to a user's account after their password is reset, due to improper session cleanup.
Exploitability
Exploitation is moderately hard as it requires the attacker to have a copy of the victim's session cookie and the ability to run the password-reset command.
Blast radius
The impact is significant as it can lead to unauthorized access and data breaches in affected deployments.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to apache-airflow-providers-fab 3.9.0 or later.
auth-bypasswebairflowsessionpassword-reset

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches and no session is removed. An attacker who already holds a copy of the victim's session cookie keeps access as that user after the password change, so the reset does not evict them. Affects deployments using the FAB auth manager with `[fab] session_backend=database`. The trigger is an administrator (or the user) running the supported password-reset command as a containment action after a session cookie has been compromised; the secure-cookie backend is out of scope, as it documents that it cannot centrally delete sessions. apache-airflow-providers-fab 3.9.0 also fixes CVE-2026-86462, a second, independent route to the same outcome via the Admin user-edit endpoint; a single upgrade closes both. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which compares the identifiers consistently.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-613

Vendors

apache

Products

apache-airflow-providers-fab

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.