CVE-2026-86473
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the victim has logged out and believes the session ended; the default token lifetime is 24 hours and is configurable.
Affects API clients that authenticate with a bearer token rather than the browser session cookie. The attacker must already possess a copy of a valid token; obtaining one is outside the scope of this issue, and no privileges beyond the victim's own are gained.
Leer descripción completaMostrar menos
Users of apache-airflow are recommended to upgrade to apache-airflow version 3.3.2 or later, which fixes the issue.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.75%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access85 %
AV:N/AC:L/PR:N permite T1190 (API expuesta). Atacante reutiliza token válido tras logout fallido para mantener acceso (T1078: uso de credenciales válidas; T1556: comprometer mecanismo autenticación).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-613
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-86473",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-86473",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-09-21T18:41:03.098800Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache Airflow",
"versions": [
{
"status": "affected",
"version": "3.0.0",
"lessThan": "3.3.2",
"versionType": "semver"
}
],
"packageURL": "pkg:pypi/apache-airflow",
"packageName": "apache-airflow",
"collectionURL": "https://pypi.python.org",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-21T15:17:32.997",
"references": [
{
"url": "https://github.com/apache/airflow/pull/72649",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread/k9z1p0q1ng8m68nlnv9d1fqzscrfm7vr",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "security@apache.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/21/5",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-613"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the victim has logged out and believes the session ended; the default token lifetime is 24 hours and is configurable.\n\nAffects API clients that authenticate with a bearer token rather than the browser session cookie. The attacker must already possess a copy of a valid token; obtaining one is outside the scope of this issue, and no privileges beyond the victim's own are gained.\n\nUsers of apache-airflow are recommended to upgrade to apache-airflow version 3.3.2 or later, which fixes the issue."
}
],
"lastModified": "2026-09-25T13:53:06.273",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5ED0276F-9088-406F-9E2A-13720DF61185",
"versionEndExcluding": "3.3.2",
"versionStartIncluding": "3.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}