目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-75156— Apache Airflow 跨租户认证绕过漏洞

一分钟漏洞结论

影响对象
Apache Software Foundation Apache Airflow FAB provider
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Apache Airflow FAB provider 版本 3.7.3 至 3.8.0 在通过 OAuth 登录时,未对 Azure AD 的 验证其颁发者(issuer)或受众(audience)。仅当 FAB 认证管理器配置了 Azure AD 作为 OAuth 提供方时,受影响部署才会出现此问题。由于签名密钥是从微软的多租户(multi-tenant)JWKS 端点获取的,因此由任意 Azure 租户——包括攻击者自行创建的租户——签发的 都能通过签名验证,随后用户名称和角色分配会从该攻击者控制的令牌中读取

AI 预测 8.1 利用难度: 中等

影响版本矩阵 1

厂商产品 版本范围状态
Apache Software Foundation Apache Airflow FAB provider 3.7.3< 3.8.1 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-75156 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
来源: CVE Program / CVE List V5
Vulnerability Description
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read from that attacker-controlled token. Anyone able to register an Azure tenant can therefore authenticate to the Airflow UI with no prior access to the deployment. The fix for **CVE-2026-59243** was incomplete, and this advisory closes the remaining gap: that fix made the provider verify the `id_token` signature, but did not add issuer or audience checks. Operators who already applied the CVE-2026-59243 fix are **still affected and must upgrade again** — 3.7.3 is the release that shipped that fix, so every version containing it falls inside this affected range. Upgrade to apache-airflow-providers-fab `3.8.1` or later.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
源验证错误
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Apache Software Foundation Apache Airflow FAB provider 3.7.3 ~ 3.8.1 -

二、漏洞 CVE-2026-75156 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-75156 的情报信息

登录查看更多情报信息。

CVE-2026-75156 补丁与修复 (1)

CVE-2026-75156 邮件列表归档 (1)

CVE-2026-75156 厂商页面 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75156

暂无评论


发表评论