Executive brief
A security flaw in the Apache Airflow FAB provider allows unauthorized users to bypass login protections when using Azure AD for authentication. By providing a specially crafted or unsigned identity token, an attacker can log in as any user, including administrators. This could lead to full control over the Airflow environment and access to sensitive data or automated workflows.
Technical details
The FAB (Flask-AppBuilder) auth manager in the Apache Airflow FAB provider incorrectly defaulted the `verify_signature` parameter to `False` during the Azure AD OAuth login flow. This vulnerability (CWE-347) allows a remote, unauthenticated attacker to present a forged ID token or an unsigned token using the 'alg:none' configuration to the OAuth callback endpoint. Because the signature is not validated against the Microsoft JWKS by default, the application accepts the identity claims within the token, enabling the attacker to impersonate any user, including those with administrative privileges. The issue is resolved in version 3.7.3, which changes the default behavior to `verify_signature=True`.
Affected products
- Apache Software Foundation Apache Airflow FAB provider (apache-airflow-providers-fab) < 3.7.3
Timeline
- 2026-07-04: other: Remediation pull request opened
- 2026-07-07: patched: Fix merged into main branch
- 2026-07-28: disclosed: Public disclosure via oss-security mailing list
- 2026-07-29: advisory: NVD publication date