CVE-2026-25604 describes a vulnerability in the AWS Auth Manager component of Apache Airflow. This flaw allows an attacker to bypass SAML authentication by manipulating the origin of the SAML authentication, enabling access to different instances with potentially varied access controls. While a CVSS score is not provided, its FAUCET Risk Score is 27/100, and it is categorized as CWE-346 (Origin Validation Error). There is no indication of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered community attention with three mentions and one media article discussing a "Host Header Injection Leading to SAML Authentication Bypass."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 9.22.0CPE matchmatch criteria | cpe:2.3:a:apache:apache-airflow-providers-amazon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
Mar 9, 2026CVE-2026-25604: Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
Mar 9, 2026