CVE-2026-86473 Overview
CVE-2026-86473 affects Apache Airflow's Core API logout endpoint. The endpoint revokes only the session token presented as the _token cookie. When an API client authenticates using an Authorization bearer header and calls logout, the endpoint returns a successful response but revokes nothing. The bearer token remains valid until its natural expiration, which defaults to 24 hours and is configurable. An attacker who already holds a copy of that token retains the victim's access after the victim believes the session has ended. This is a session management flaw classified under CWE-613 (Insufficient Session Expiration).
Critical Impact
A logged-out victim's bearer token remains valid for up to 24 hours, allowing an attacker with a stolen token to continue accessing the Apache Airflow Core API with the victim's privileges.
Affected Products
- Apache Airflow Core API (versions prior to 3.3.2)
- API clients authenticating with bearer tokens via Authorization header
- Deployments relying on the logout endpoint to terminate token-based sessions
Discovery Timeline
- 2026-09-21 - CVE-2026-86473 published to the National Vulnerability Database (NVD)
- 2026-09-21 - Disclosed publicly via the Apache Airflow mailing list and OpenWall OSS-Security
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-86473
Vulnerability Analysis
Apache Airflow exposes a Core API logout endpoint intended to invalidate the caller's authentication credential. The implementation inspects the request for a session token stored in the _token cookie and revokes only that value. Bearer tokens supplied through the Authorization: Bearer <token> header are never processed by the revocation path. The endpoint still returns a normal HTTP success response, giving the caller the false impression that the session has ended.
The result is that any bearer token issued to a client remains valid until its expiration time elapses. With the default lifetime of 24 hours, a stolen or copied token grants continued API access long after the legitimate user has logged out. The attacker gains no new privileges beyond the victim's own, but persistence of access is the defining risk.
Root Cause
The root cause is inconsistent handling of authentication credentials between the login and logout paths. The API accepts both cookie-based and bearer-header authentication for normal operations, but the logout logic revokes only the cookie-bound token. Bearer tokens are treated as stateless and are never added to a revocation list or short-lived denylist. This constitutes an insufficient session expiration weakness under CWE-613.
Attack Vector
Exploitation requires the attacker to already possess a valid bearer token belonging to the victim. Token theft is out of scope for this issue but can result from phishing, log exposure, intercepted CI/CD secrets, or client-side compromise. Once the victim initiates logout using bearer authentication, the API responds successfully while leaving the token active. The attacker continues to send authenticated requests to the Core API using the same token, retaining full access at the victim's privilege level until the token's configured lifetime expires. The attack requires no user interaction from the victim beyond the logout action they initiate themselves.
See the GitHub Pull Request #72649 for the fix implementation details.
Detection Methods for CVE-2026-86473
Indicators of Compromise
- API activity from a user account continuing after that user's logout event has been recorded in application logs.
- Bearer token usage from unexpected source IP addresses or user agents shortly after a legitimate logout.
- Long-lived tokens observed in access logs beyond typical user session windows.
Detection Strategies
- Correlate logout events with subsequent Core API requests that carry the same bearer token identifier or JWT jti claim.
- Baseline normal token usage patterns per user and alert on continued activity following an explicit logout.
- Inspect API gateway or reverse-proxy logs for Authorization: Bearer requests occurring after /logout responses for the same principal.
Monitoring Recommendations
- Enable verbose authentication and API access logging on all Apache Airflow deployments.
- Forward Airflow API logs to a centralized analytics pipeline for correlation across logout and post-logout activity windows.
- Track token issuance and last-use timestamps to identify tokens active beyond expected session durations.
How to Mitigate CVE-2026-86473
Immediate Actions Required
- Upgrade Apache Airflow to version 3.3.2 or later, which contains the fix for the logout endpoint.
- Rotate any bearer tokens issued to API clients that may have been exposed prior to the upgrade.
- Reduce the configured bearer token lifetime to minimize the exposure window until patching is complete.
Patch Information
The Apache Airflow project released version 3.3.2 to address CVE-2026-86473. The fix ensures the Core API logout endpoint revokes credentials presented via both the _token cookie and the Authorization bearer header. Refer to GitHub Pull Request #72649, the Apache Mailing List Thread, and the OpenWall OSS-Security Update for details.
Workarounds
- Shorten the token lifetime configuration so revoked-in-name-only tokens expire quickly after logout.
- Restrict API access to trusted networks or require mutual TLS in front of the Airflow API to reduce the value of stolen tokens.
- Instruct API clients to treat logout as advisory and to rotate bearer tokens on every authentication cycle until the upgrade is applied.
# Configuration example: reduce Airflow API JWT token lifetime
# Set a shorter expiration in airflow.cfg to limit exposure of unrevoked tokens
[api]
auth_jwt_expiration_time = 900 # 15 minutes instead of the 24-hour default
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
