Severity: Moderate 

Affected versions:

- Apache Airflow FAB provider (apache-airflow-providers-fab) before 3.6.4

Description:

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability 
(CWE-90) that allows unauthenticated attackers to exfiltrate directory data or 
bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. 
If immediate upgrade is not possible, disable LDAP authentication until the 
provider can be updated.

Credit:

Venkatraman Kumar (r3dw0lfsec), Securin (finder)
orbisai0security (automated scanner — Orbis Security AI) (remediation developer)

References:

https://github.com/apache/airflow/pull/66417
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-46745

Reply via email to