Medium severity5.3NVD Advisory· Published May 25, 2026· Updated Jul 23, 2026
CVE-2026-46745
CVE-2026-46745
Description
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-fabPyPI | < 3.6.4 | 3.6.4 |
Affected products
3- Range: <3.6.4
cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:apache-airflow-providers-fab:*:*:*:*:*:*:*:*range: <3.6.4
- (no CPE)range: >=3.6.4
Patches
Vulnerability mechanics
References
6- github.com/apache/airflow/pull/66417nvdIssue TrackingPatchWEB
- www.openwall.com/lists/oss-security/2026/05/24/10nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-g283-w6fp-c4fcghsaADVISORY
- lists.apache.org/thread/dvfy0bs181xwsrjrd3y5c55ztbzm8yhhnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-46745ghsaADVISORY
- github.com/apache/airflow/commit/3f7756bea71a7c7988511ec0557314ffb15fbe5eghsaWEB
News mentions
1- Apache Ships 12 Patches Across 7 Projects: Shiro, Airflow, Syncope Lead the BatchVypr Intelligence · May 28, 2026