https://seclists.org/oss-sec/2026/q3/794: CVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
Published Sep 15, 2026
·Updated
Affected Software
1 affected component
apache-airflow-providers-fab<3.9.0
Frequently Asked Questions
1
Which deployments are affected?
Affected deployments use the FAB auth manager with database-backed sessions and apache-airflow-providers-fab versions from 3.2.0 before 3.9.0.
2
What does an attacker need to retain access after a password change?
The attacker must already possess a copy of the victim's session cookie. No attacker interaction with the Admin user-edit PATCH endpoint is required when the password is changed.
3
Does the earlier fix for CVE-2026-82311 address this issue?
No. This issue follows a separate path because the Admin user-edit PATCH endpoint does not call the session-invalidation helper, so deployments that applied the CVE-2026-82311 fix must also upgrade.
4
What should be done if a deployment is affected?
Upgrade apache-airflow-providers-fab to version 3.9.0 or later. That version fixes the missing session invalidation on this password-change path.