CVE-2026-46745
published 2026-05-25CVE-2026-46745: Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or…
PriorityP338medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.57%
43.6th percentile
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache-airflow-providers-fab | < 3.6.4 | 3.6.4 |
| apache | apache-airflow-providers-fab | >= 0 < 3.6.4 | 3.6.4 |
| apache_software_foundation | apache_airflow_fab_provider | < 3.6.4 | 3.6.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g283-w6fp-c4fc: Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory
ghsa_unreviewed·2026-05-26
CVE-2026-46745 [MEDIUM] CWE-90 GHSA-g283-w6fp-c4fc: Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.
GHSA
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
ghsa·2026-05-26
CVE-2026-46745 [MEDIUM] CWE-90 Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.
CVEList
Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token
cvelistv5·2026-05-25
CVE-2026-46745 CWE-90 Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token
Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.
VulDB
Apache Airflow FAB provider up to 3.6.3 ldap injection (EUVD-2026-31669)
vuldb·2026-05-25
CVE-2026-46745 [CRITICAL] Apache Airflow FAB provider up to 3.6.3 ldap injection (EUVD-2026-31669)
A vulnerability was found in Apache Airflow FAB provider up to 3.6.3. It has been declared as critical. This issue affects some unknown processing. The manipulation results in ldap injection.
This vulnerability is known as CVE-2026-46745. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-25
Published