Skip to main content
CRITICAL

CVE-2026-86473

Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry

CVSS v3

9.1

CRITICAL

EPSS Score

0.7 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the victim has logged out and believes the session ended; the default token lifetime is 24 hours and is c

Technical details

Published
2026-09-21
Last Modified
2026-09-21

Frequently asked questions

What is CVE-2026-86473?

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the victim has logged out and believes the session ended; the default token lifetime is 24 hours and is c

Is CVE-2026-86473 actively exploited?

Active exploitation of CVE-2026-86473 has not been confirmed. Its EPSS score was 0.7% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-86473?

CVE-2026-86473 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2026-86473 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key