CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6778

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to verify the issuer and audience claims in Azure AD identity tokens during OAuth authentication. This omission permits attackers from other Azure AD tenants to gain unauthorized access to affected deployments configured with Azure AD as the OAuth provider.

Why it matters: Organizations running Airflow with Azure AD OAuth authentication are exposed to cross-tenant account hijacking; upgrade to version 3.8.1 or later immediately.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 contain a validation flaw in Azure AD OAuth authentication that allows attackers to bypass cross-tenant restrictions. The vulnerability stems from missing issuer and audience checks on ID tokens, affecting deployments using FAB as the authentication manager with Azure AD.

Why it matters: Organizations using Apache Airflow with Azure AD OAuth authentication can be compromised by attackers from different tenants; upgrade FAB provider to 3.8.1 or later immediately.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to verify the issuer and audience claims in Azure AD identity tokens during OAuth authentication. This omission allows attackers from other Azure tenants to authenticate as legitimate users when the FAB auth manager uses Azure AD as an OAuth provider.

Why it matters: Organizations running Airflow with FAB provider and Azure AD OAuth are exposed to cross-tenant account takeover; upgrade to version 3.8.1 or later immediately.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience claims in Azure Active Directory identity tokens during OAuth authentication. This omission permits attackers from other Azure AD tenants to gain unauthorized access to affected Airflow instances. The vulnerability was addressed in version 3.8.1.

Why it matters: Organizations running Airflow with Azure AD OAuth using the vulnerable FAB provider versions face cross-tenant authentication bypass, allowing external attackers to access Airflow deployments and workflows; patching to 3.8.1 or later is required immediately.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 skip validation of issuer and audience claims in Azure Active Directory (AD) identity tokens during OAuth authentication. This permits attackers from other Azure AD tenants to authenticate as legitimate users on affected systems.

Why it matters: Organizations using Apache Airflow with Azure AD OAuth authentication must upgrade to version 3.8.1 or later to prevent cross-tenant authentication bypass and unauthorized access to workflow systems.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience claims in Azure Active Directory (AD) id_tokens during OAuth authentication. This allows attackers from other Azure AD tenants to bypass authentication and gain unauthorized access to Airflow instances configured with Azure AD OAuth.

Why it matters: Organizations running Airflow with Azure AD OAuth are at immediate risk of cross-tenant authentication bypass; patching to version 3.8.1 or later is required to prevent unauthorized access.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to verify the issuer and audience claims in Azure Active Directory id_tokens during OAuth authentication. This allows attackers from other Azure AD tenants to bypass authentication if the application is configured to use Azure AD as its OAuth provider.

Why it matters: Organizations running Apache Airflow with Azure AD OAuth are vulnerable to cross-tenant authentication bypass; patching to version 3.8.1 or later is necessary to validate token claims properly.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience claims in Azure AD id_tokens during OAuth authentication. This allows attackers to bypass cross-tenant authentication restrictions and gain unauthorized access to Airflow deployments configured with Azure AD as the OAuth provider.

Why it matters: Organizations running Apache Airflow with Azure AD OAuth authentication need to upgrade to version 3.8.1 or later immediately to prevent unauthorized access from external Azure AD tenants.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience claims in Azure Active Directory (AD) id_tokens during OAuth authentication. This allows attackers from other Azure AD tenants to gain unauthorized access to affected deployments configured to use Azure AD as an OAuth provider.

Why it matters: Organizations running Airflow with Azure AD OAuth are exposed to cross-tenant authentication bypass; upgrade to version 3.8.1 or later immediately to restore proper token validation.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to verify the issuer and audience claims in Azure Active Directory (AD) id_tokens during OAuth authentication. This allows attackers from other Azure AD tenants to bypass authentication and gain unauthorized access to affected deployments.

Why it matters: Organizations running Apache Airflow with Azure AD OAuth configured are at risk of cross-tenant authentication bypass; patching to version 3.8.1 or later is required immediately.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience claims in Azure AD identity tokens during OAuth authentication. This allows attackers to forge tokens from other Azure tenants and gain unauthorized access to affected deployments that use Azure AD as their OAuth provider.

Why it matters: Organizations running Apache Airflow with Azure AD authentication must upgrade to version 3.8.1 or later immediately to prevent cross-tenant account takeover.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to verify the issuer and audience claims in Azure Active Directory (AD) id_tokens during OAuth authentication. This omission permits attackers from other Azure AD tenants to authenticate as legitimate users when the FAB auth manager relies on Azure AD for OAuth.

Why it matters: Organizations running affected versions of Apache Airflow with Azure AD OAuth are exposed to cross-tenant account takeover; upgrade to version 3.8.1 or later immediately.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience fields in Azure Active Directory (AD) id_tokens during OAuth authentication. This permits attackers to forge valid authentication tokens from other Azure AD tenants, bypassing the expected organizational boundary. The flaw affects deployments where the FAB auth manager is configured to use Azure AD as the OAuth provider.

Why it matters: Organizations running vulnerable Airflow FAB provider versions with Azure AD OAuth are exposed to cross-tenant authentication bypass, allowing attackers from other tenants to gain unauthorized access to Airflow instances; immediate upgrade to version 3.8.1 or later is required.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to verify the issuer and audience claims in Azure AD identity tokens during OAuth authentication. This allows an attacker to forge valid tokens from other Azure tenants and gain unauthorized access to affected Airflow deployments. The vulnerability affects only systems using FAB as the authentication manager with Azure AD as the OAuth provider.

Why it matters: Organizations running Apache Airflow with Azure AD OAuth are exposed to cross-tenant authentication bypass and should upgrade to version 3.8.1 or later immediately to prevent unauthorized access.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience claims in Azure AD id_tokens during OAuth authentication, allowing attackers from other Azure tenants to gain unauthorized access. The vulnerability affects only deployments using FAB's Azure AD OAuth configuration. A patch is available in version 3.8.1 and later.

Why it matters: Organizations running affected Airflow instances with Azure AD OAuth are exposed to cross-tenant account takeover; upgrade FAB provider to 3.8.1 or later immediately.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated - cross-tenant authentication bypass

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 fail to validate the issuer and audience claims in Azure AD identity tokens during OAuth authentication. This gap allows attackers from other Azure AD tenants to gain unauthorized access to affected deployments configured with Azure AD as the OAuth provider.

Why it matters: Organizations running Apache Airflow with Azure AD OAuth authentication need to upgrade to version 3.8.1 or later to prevent cross-tenant account hijacking.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary