Report: CVE-2026-46745 - Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_l

Report: CVE-2026-46745 - Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_l

CVE ID :CVE-2026-46745 Published : 25 May 2026, 10:41 a.m. | 1 hour, 16 minutes ago Description :Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Affected Product: Apache
CWE: CWE-90