SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59243

CRITICAL · CVSS 9.8 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The FAB auth manager in Apache is vulnerable due to a misconfiguration that allows an attacker to bypass authentication by presenting a forged or unsigned ID token, potentially gaining access as any user, including those with Admin privileges. This critical vulnerability affects deployments using the Azure AD OAuth login with default settings, specifically in versions prior to 3.7.3 of `apache-airflow-providers-fab`. Organizations utilizing this configuration should prioritize upgrading to version 3.7.3 or later to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59243
Severity
CRITICAL
CVSS
9.8
EPSS
0.45%
Apache

Original NVD Description

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.

Related CVEs

Other vulnerabilities affecting the same vendor(s)