THREAT OPS › Threat News › CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
<p>Posted by Vincent Beck on Sep 15</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Airflow FAB provider (apache-airflow-providers-fab) 2.0.0 before 3.9.0<br /> <br /> Description:<br /> <br /> Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before <br /> deactivation. Password authentication correctly rejects the di
Indicators of compromise
- CVE-2026-82310cve
Original source: https://seclists.org/oss-sec/2026/q3/792