{"id":"CVE-2026-82355","published":"2026-09-21T15:17:32.430","lastModified":"2026-09-21T19:17:12.793","description":"When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the cookie's principal rather than the identity the client explicitly presented.\n\nOnly Apache Airflow 3.3.0 and 3.3.1 are affected. Earlier releases do not contain the code path that caches the cookie-derived user, and are not vulnerable.\n\nExploiting this requires an attacker to first place a valid session cookie of their own into the victim's browser or client: for example by cookie tossing from a sibling subdomain, through cross-site scripting in a separate application sharing a parent domain, or via a shared workstation. Deployments that host the Airflow UI on a domain shared with other applications are therefore the most exposed; a deployment on a dedicated domain with no co-hosted applications is not reachable this way. The consequence is principal confusion and misattributed audit records rather than a direct privilege escalation.\n\nUsers of 3.3.0 or 3.3.1 should upgrade to Apache Airflow 3.3.2 or later, which resolves the caller from the explicitly supplied credential whenever one is present.","cvssScore":4.2,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","cwes":["CWE-384"],"vendors":[],"products":[],"references":[{"url":"https://github.com/apache/airflow/pull/72225","tags":[]},{"url":"https://github.com/apache/airflow/pull/72723","tags":[]},{"url":"https://lists.apache.org/thread/3p7zpdvv40tn01m0xk5mt2rxg88mw8w1","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/21/4","tags":[]}],"exploitRefs":[{"url":"https://github.com/apache/airflow/pull/72225","tags":[]},{"url":"https://github.com/apache/airflow/pull/72723","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows an attacker to bypass intended authentication by using a session cookie and an explicit bearer token, with Airflow resolving the caller from the cookie instead of the token.","exploitability":"Exploitation requires placing a valid session cookie in the victim's browser or client, making it moderately difficult but feasible through various attack vectors like cross-site scripting or shared workstations.","blast_radius":"If exploited, this could lead to principal confusion and misattributed audit records, impacting trust and accountability within the system.","remediation":"Upgrade Apache Airflow to version 3.3.2 or later to ensure the caller is resolved from the explicitly supplied credential whenever one is present.","tags":["auth-bypass","web","api","cookie","token"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:35:07.626Z"}}