Insufficient Session Expiration Affecting apache-airflow-providers-fab package, versions [2.0.0, 3.9.0rc1)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1% (62nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSFAB-19882868
  • published17 Sept 2026
  • disclosed16 Sept 2026
  • creditMayank Jangid (OpenSec)

Introduced: 16 Sep 2026

NewCVE-2026-82310  (opens in a new tab)
CWE-613  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-fab to version 3.9.0rc1 or higher.

Overview

apache-airflow-providers-fab is a Provider package apache-airflow-providers-fab for Apache Airflow

Affected versions of this package are vulnerable to Insufficient Session Expiration due to the Core API accepting existing, unexpired tokens for accounts that have been deactivated by an administrator. An attacker can maintain role-scoped access by replaying their own legitimate credential and minting replacement tokens, even after their account has been disabled.

Note: This is only exploitable if the deployment uses Airflow 3 with the FAB auth manager and Core API token authentication, and the deactivated account's row remains in the database with a previously issued, unexpired token.

CVSS Base Scores

version 4.0
version 3.1