In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.
This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances.
You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.
References
| Link | Resource |
|---|---|
| https://github.com/apache/airflow/pull/61368 | Issue Tracking Patch |
| https://lists.apache.org/thread/spwwrsmwxod7fpttcd7n7zs46j839l77 | Mailing List |
| http://www.openwall.com/lists/oss-security/2026/03/09/6 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-09 11:16
Updated : 2026-03-10 18:58
NVD link : CVE-2026-25604
Mitre link : CVE-2026-25604
CVE.ORG link : CVE-2026-25604
JSON object : View
Products Affected
apache
- airflow_providers_amazon
CWE
CWE-346
Origin Validation Error
