CVE-2026-82355 Overview
CVE-2026-82355 affects the Apache Airflow core API in versions 3.3.0 and 3.3.1. When a request presents both a session cookie and an explicit Authorization: Bearer token, Airflow resolves the caller from the cookie and ignores the bearer token. This inverts the intended precedence where bearer credentials should override cookies. The request executes, and is recorded in the audit log, under the cookie's principal rather than the identity the client explicitly presented. The flaw is tracked under CWE-384: Session Fixation.
Critical Impact
Requests execute under the wrong principal, producing misattributed audit records and enabling principal confusion in deployments where an attacker can plant a session cookie in the victim's client.
Affected Products
- Apache Airflow 3.3.0
- Apache Airflow 3.3.1
- Apache Airflow deployments hosting the UI on a domain shared with other applications
Discovery Timeline
- 2026-09-21 - CVE CVE-2026-82355 published to NVD
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-82355
Vulnerability Analysis
Apache Airflow 3.3.0 introduced a code path that caches the user derived from a session cookie during request authentication. When the core API receives a request carrying both a cookie and an Authorization: Bearer header, the cached cookie principal wins. The bearer token is silently discarded rather than taking precedence.
The downstream effect is that all authorization decisions, task actions, and audit log entries associate with the cookie owner. A client that explicitly presents a bearer token expects that identity to be authoritative. That expectation does not hold in the affected releases.
This is a principal confusion issue rather than a direct privilege escalation. An attacker does not gain new permissions through the flaw itself. Instead, the identity attribution boundary between two authenticated principals breaks, corrupting the audit trail and enabling attacker actions to be logged under a victim's name.
Root Cause
The authentication middleware in Airflow 3.3.0 and 3.3.1 resolves and caches the cookie-derived user before evaluating other credentials on the request. Once cached, the bearer token path is skipped. Earlier releases lack this caching logic and enforce bearer precedence correctly.
Attack Vector
Exploitation requires the attacker to place a valid session cookie of their own into the victim's browser or client. Feasible techniques include cookie tossing from a sibling subdomain, cross-site scripting in a co-hosted application sharing a parent domain, or a shared workstation. Deployments that host the Airflow UI on a dedicated domain with no co-located applications are not reachable through these vectors.
The vulnerability requires user interaction and a high-complexity attack chain, which is reflected in the modest exploitability profile. See the Apache Mailing List Thread and the OpenWall OSS Security Post for further disclosure detail.
Detection Methods for CVE-2026-82355
Indicators of Compromise
- Airflow audit log entries showing actions attributed to a principal whose session cookie is present alongside an unrelated bearer token in the same request.
- API requests to the Airflow core API containing both a Cookie header and an Authorization: Bearer header where the two identities differ.
- Unexpected task triggers, DAG modifications, or configuration changes recorded under service accounts or human users who did not initiate them.
Detection Strategies
- Instrument the reverse proxy or ingress in front of Airflow to log requests that carry both a session cookie and an Authorization header, then correlate with audit log principals.
- Compare bearer token subject claims against the audit log principal for the same request identifier to detect divergence.
- Alert on Airflow API calls originating from browsers or clients on domains that share a parent with the Airflow UI host.
Monitoring Recommendations
- Forward Airflow webserver access logs and audit records to a centralized analytics pipeline for cross-field correlation.
- Monitor for XSS activity and cookie-setting responses on sibling subdomains of the Airflow deployment.
- Track upgrade status of all Airflow deployments to identify hosts still running 3.3.0 or 3.3.1.
How to Mitigate CVE-2026-82355
Immediate Actions Required
- Upgrade Apache Airflow to version 3.3.2 or later, which resolves the caller from the explicitly supplied credential when one is present.
- Inventory all Airflow deployments to confirm which run 3.3.0 or 3.3.1 and prioritize those on shared parent domains.
- Review recent audit logs for actions attributed to unexpected principals during the exposure window.
Patch Information
The fix ships in Apache Airflow 3.3.2. The corrective changes are tracked in GitHub Pull Request #72225 and GitHub Pull Request #72723. Both restore bearer precedence and remove the cookie-user caching behavior that produced the confusion.
Workarounds
- Host the Airflow UI on a dedicated domain with no co-located applications to eliminate the cookie-tossing and shared-parent XSS vectors.
- Configure the reverse proxy to strip session cookies from requests that carry an Authorization: Bearer header before they reach Airflow.
- Set the session cookie Domain attribute as narrowly as possible and enable SameSite=Strict to reduce cross-context cookie planting.
# Configuration example
# Upgrade Apache Airflow using pip
pip install --upgrade 'apache-airflow==3.3.2'
# Verify the installed version
airflow version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
