CVE-2026-59243: CWE-347: Improper Verification of Cryptographic Signature in Apache Software Foundation Apache Airflow FAB provider
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
AI Analysis
Technical Summary
The Apache Airflow FAB provider's Azure AD OAuth login path had a default configuration where the ID token's cryptographic signature verification was disabled (`verify_signature=False`). This improper verification (CWE-347) allows an attacker who can present a forged or unsigned (`alg:none`) ID token to bypass authentication and log in as any user, including admins. The vulnerability affects all versions of `apache-airflow-providers-fab` prior to 3.7.3. The Authentik OAuth path was not affected as it already enforced signature verification. The vendor fixed the issue by changing the default to `verify_signature=True` in version 3.7.3.
Potential Impact
An attacker can bypass authentication by presenting a forged or unsigned ID token, gaining unauthorized access to the system as any user, including those with administrative privileges. This leads to full compromise of the affected Apache Airflow deployments using the vulnerable FAB provider with Azure AD OAuth login under default settings. The CVSS score of 9.8 reflects the critical impact with network attack vector, no privileges or user interaction required, and high confidentiality, integrity, and availability impacts.
Mitigation Recommendations
A patch is available in `apache-airflow-providers-fab` version 3.7.3, which changes the default setting to verify cryptographic signatures on ID tokens (`verify_signature=True`). Users should upgrade to version 3.7.3 or later to remediate this vulnerability. Since this is a cloud service component, the vendor manages remediation for cloud-hosted deployments; users should verify their environment is updated accordingly.
CVE-2026-59243: CWE-347: Improper Verification of Cryptographic Signature in Apache Software Foundation Apache Airflow FAB provider
Description
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
CVSS v3.1
Score 9.8critical
Affected software
Apache Software Foundation
Apache Airflow FAB provider
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Apache Airflow FAB provider's Azure AD OAuth login path had a default configuration where the ID token's cryptographic signature verification was disabled (`verify_signature=False`). This improper verification (CWE-347) allows an attacker who can present a forged or unsigned (`alg:none`) ID token to bypass authentication and log in as any user, including admins. The vulnerability affects all versions of `apache-airflow-providers-fab` prior to 3.7.3. The Authentik OAuth path was not affected as it already enforced signature verification. The vendor fixed the issue by changing the default to `verify_signature=True` in version 3.7.3.
Potential Impact
An attacker can bypass authentication by presenting a forged or unsigned ID token, gaining unauthorized access to the system as any user, including those with administrative privileges. This leads to full compromise of the affected Apache Airflow deployments using the vulnerable FAB provider with Azure AD OAuth login under default settings. The CVSS score of 9.8 reflects the critical impact with network attack vector, no privileges or user interaction required, and high confidentiality, integrity, and availability impacts.
Mitigation Recommendations
A patch is available in `apache-airflow-providers-fab` version 3.7.3, which changes the default setting to verify cryptographic signatures on ID tokens (`verify_signature=True`). Users should upgrade to version 3.7.3 or later to remediate this vulnerability. Since this is a cloud service component, the vendor manages remediation for cloud-hosted deployments; users should verify their environment is updated accordingly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-07-04T00:18:03.606Z
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6a69c9f59c2644c7f8487eee
Added to database: 07/29/2026, 09:37:57 UTC
Last enriched: 08/05/2026, 14:51:45 UTC
Last updated: 09/12/2026, 17:04:04 UTC
Views: 155
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.