https://seclists.org/oss-sec/2026/q3/793: CVE-2026-82311: Apache Airflow FAB provider: FAB password set never invalidates sessions: string/int _user_id comparison is always false
Affected Software
Frequently Asked Questions
Which deployments are affected by this issue?
Affected deployments use the FAB auth manager with [fab] session_backend=database and apache-airflow-providers-fab versions from 2.4.2 before 3.9.0. Deployments using the secure-cookie session backend are out of scope.
What must an attacker have to retain access after a password reset?
The attacker must already possess a copy of the victim's session cookie. They can continue using that session after the victim or an administrator resets the password because the existing database-backed session is not removed.
Does a password reset contain a compromised session on affected systems?
No. On affected database-backed-session deployments, the supported password-reset command does not evict the user's existing sessions, despite the documented behavior.
What remediation is available?
Upgrade apache-airflow-providers-fab to 3.9.0. This upgrade also fixes CVE-2026-86462, an independent issue involving the Admin user-edit endpoint that can lead to the same session-persistence outcome.