CRITICAL
9.1 CVE-2026-86462 Published 16 Sept 2026
Apache Airflow FAB Auth Manager Password Change Session Hijack
Worried this affects your website?
In Apache Airflow with FAB auth manager and database-backed sessions, changing a user's password through the Admin user-edit PATCH endpoint does not invalidate their existing sessions.
An attacker with a copied session cookie retains full access as that user after the password change. No attacker interaction with the endpoint is required.
Apache Airflow users with FAB auth manager should upgrade to version 3.9.0 or later to fix this issue.
Reference: CVE-2026-86462 on NVD
← Back to Security News