{"id":"CVE-2026-46745","aliases":["GHSA-g283-w6fp-c4fc","PYSEC-2026-2366"],"url":"https://o3.security/vulnerability/CVE-2026-46745","summary":"Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token","details":"Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.","published":"2026-05-25T10:41:16.676Z","modified":"2026-08-12T03:51:48.889012472Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.00575,"percentile":0.44716,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"apache-airflow-providers-fab","fixedVersion":"3.6.4"}],"fix":{"url":"https://github.com/apache/airflow/pull/66417","label":"apache/airflow#66417"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/24/10"},{"type":"WEB","url":"https://pypi.python.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46745.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/dvfy0bs181xwsrjrd3y5c55ztbzm8yhh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46745"},{"type":"FIX","url":"https://github.com/apache/airflow/pull/66417"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.889012472Z"}}