CVE-2026-59243: CWE-347: Improper Verification of Cryptographic Signature in Apache Software Foundation Apache Airflow FAB provider
CVE-2026-59243 is a vulnerability in the Apache Airflow FAB provider where the Azure AD OAuth login defaulted to not verifying the cryptographic signature of ID tokens. This allowed attackers to bypass authentication by presenting forged or unsigned tokens, potentially gaining arbitrary user access including admin roles. The issue affects deployments using the FAB auth manager with default Azure AD OAuth login settings prior to version 3.7.3. The vulnerability is fixed in version 3.7.3, which enables signature verification by default.
AI Analysis
Technical Summary
The Apache Airflow FAB provider's Azure AD OAuth login component had a security flaw where the ID token signature verification was disabled by default (`verify_signature=False`). This improper verification (CWE-347) allowed an attacker to supply a forged or unsigned ID token (e.g., with `alg:none`) to the OAuth callback endpoint, bypassing authentication controls and logging in as any user, including administrators. The issue specifically affects versions of `apache-airflow-providers-fab` before 3.7.3. The fix in 3.7.3 changes the default to `verify_signature=True`, mitigating the risk. The Authentik login path was not affected as it already enforced signature verification.
Potential Impact
An attacker able to present a forged or unsigned ID token to the vulnerable OAuth login endpoint can bypass authentication and gain unauthorized access as any user, including those with administrative privileges. This compromises the authentication mechanism, potentially allowing full control over the affected Airflow deployment's FAB provider authentication.
Mitigation Recommendations
A patch is available in `apache-airflow-providers-fab` version 3.7.3, which changes the default setting to verify cryptographic signatures on ID tokens. Users should upgrade to version 3.7.3 or later to mitigate this vulnerability. Since this is a cloud service, the vendor typically manages remediation server-side; users should verify with the vendor advisory for their deployment environment. No other mitigations are specified.
CVE-2026-59243: CWE-347: Improper Verification of Cryptographic Signature in Apache Software Foundation Apache Airflow FAB provider
Description
CVE-2026-59243 is a vulnerability in the Apache Airflow FAB provider where the Azure AD OAuth login defaulted to not verifying the cryptographic signature of ID tokens. This allowed attackers to bypass authentication by presenting forged or unsigned tokens, potentially gaining arbitrary user access including admin roles. The issue affects deployments using the FAB auth manager with default Azure AD OAuth login settings prior to version 3.7.3. The vulnerability is fixed in version 3.7.3, which enables signature verification by default.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Apache Airflow FAB provider's Azure AD OAuth login component had a security flaw where the ID token signature verification was disabled by default (`verify_signature=False`). This improper verification (CWE-347) allowed an attacker to supply a forged or unsigned ID token (e.g., with `alg:none`) to the OAuth callback endpoint, bypassing authentication controls and logging in as any user, including administrators. The issue specifically affects versions of `apache-airflow-providers-fab` before 3.7.3. The fix in 3.7.3 changes the default to `verify_signature=True`, mitigating the risk. The Authentik login path was not affected as it already enforced signature verification.
Potential Impact
An attacker able to present a forged or unsigned ID token to the vulnerable OAuth login endpoint can bypass authentication and gain unauthorized access as any user, including those with administrative privileges. This compromises the authentication mechanism, potentially allowing full control over the affected Airflow deployment's FAB provider authentication.
Mitigation Recommendations
A patch is available in `apache-airflow-providers-fab` version 3.7.3, which changes the default setting to verify cryptographic signatures on ID tokens. Users should upgrade to version 3.7.3 or later to mitigate this vulnerability. Since this is a cloud service, the vendor typically manages remediation server-side; users should verify with the vendor advisory for their deployment environment. No other mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-07-04T00:18:03.606Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a69c9f59c2644c7f8487eee
Added to database: 07/29/2026, 09:37:57 UTC
Last enriched: 07/29/2026, 10:23:57 UTC
Last updated: 07/29/2026, 10:23:57 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.