CVE-2026-25604
Estado: AnalizadaMedia (5.4)—
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances.
You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-346
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-25604",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-25604",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-09T16:47:57.674471Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache Airflow Providers Amazon",
"versions": [
{
"status": "affected",
"version": "8.0.0",
"lessThan": "9.22.0",
"versionType": "semver"
}
],
"packageName": "apache-airflow-providers-amazon",
"collectionURL": "https://pypi.python.org",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-09T11:16:06.077",
"references": [
{
"url": "https://github.com/apache/airflow/pull/61368",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread/spwwrsmwxod7fpttcd7n7zs46j839l77",
"tags": [
"Mailing List"
],
"source": "security@apache.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/03/09/6",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-346"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. \nThis allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances.\n\nYou should upgrade to 9.22.0 version of provider if you use AWS Auth Manager."
},
{
"lang": "es",
"value": "En el gestor de AWS Auth, el origen de la autenticación SAML se ha utilizado tal como lo proporcionó el cliente y no se ha verificado contra la URL real de la instancia.\nEsto permitió obtener acceso a diferentes instancias con controles de acceso potencialmente diferentes al reutilizar la respuesta SAML de otras instancias.\n\nDebería actualizarse a la versión 9.22.0 del proveedor si utiliza el gestor de AWS Auth."
}
],
"lastModified": "2026-07-02T16:35:27.977",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:apache-airflow-providers-amazon:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D7E7AEF-0618-4850-ABD5-A80E90CD8F6D",
"versionEndExcluding": "9.22.0",
"versionStartIncluding": "8.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}