https://seclists.org/oss-sec/2026/q3/795: CVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
Published Sep 15, 2026
·Updated
Affected Software
1 affected component
apache-airflow-providers-fab<3.9.0
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using the FAB auth manager with Authentik OAuth are affected when the same Authentik instance also serves other client applications. Apache Airflow FAB provider versions before 3.9.0 are affected.
2
What does an attacker need to exploit it?
The attacker needs a valid token issued by that Authentik identity provider for another client application. They do not need a token issued specifically for Airflow.
3
Does applying the earlier Azure AD validation fix address this issue?
No. CVE-2026-75156 corrected missing validation on the Azure AD path, while the Authentik path remained affected; deployments using Authentik need this separate upgrade.
4
What is the recommended remediation?
Upgrade apache-airflow-providers-fab to version 3.9.0 or later.