Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false
Summary
| CVE | CVE-2026-82311 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 09:17:06 UTC |
| Updated | 2026-09-16 09:17:06 UTC |
| Description | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches and no session is removed. An attacker who already holds a copy of the victim's session cookie keeps access as that user after the password change, so the reset does not evict them. Affects deployments using the FAB auth manager with `[fab] session_backend=database`. The trigger is an administrator (or the user) running the supported password-reset command as a containment action after a session cookie has been compromised; the secure-cookie backend is out of scope, as it documents that it cannot centrally delete sessions. apache-airflow-providers-fab 3.9.0 also fixes CVE-2026-86462, a second, independent route to the same outcome via the Admin user-edit endpoint; a single upgrade closes both. Users of apache-airflow-providers-fab are recommended to upgrade to version 3.9.0 or later, which compares the identifiers consistently. |
Risk And Classification
Problem Types: CWE-613 | CWE-613 CWE-613: Insufficient Session Expiration
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Airflow FAB Provider | affected 2.4.2 3.9.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/apache/airflow/pull/72198 | [email protected] | github.com | |
| lists.apache.org/thread/mmplwl93shy615shkpp9p4fzyjvr4yqw | [email protected] | lists.apache.org | |
| www.cve.org/CVERecord | [email protected] | www.cve.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Mayank Jangid (OpenSec) (en)
CNA: Jarek Potiuk (en)
There are currently no legacy QID mappings associated with this CVE.