CVE-2026-59243 is an authentication-bypass vulnerability in the Apache Airflow FAB provider's FAB auth manager when Azure AD OAuth authentication is used. In affected versions of apache-airflow-providers-fab before 3.7.3, the Azure AD OAuth login path decoded ID tokens with signature verification disabled by default. Consequently, the OAuth callback could accept a forged or unsigned JWT, including one using the alg:none algorithm, and use its identity and role claims for login. The Authentik login path was not affected because it enabled signature verification by default.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC consisting of a README and a single Python script, exploit.py. It targets CVE-2026-59243 in Apache Airflow's FAB auth manager provider for Azure OAuth, where id_token signature verification is disabled by default in vulnerable apache-airflow-providers-fab versions. The exploit abuses this to complete the OAuth flow and obtain an authenticated Airflow Admin session without valid credentials, then uses the resulting API token to trigger a DAG run that executes attacker-controlled commands. Repository structure is minimal: README.md documents the vulnerability, affected/fixed versions, prerequisites, and usage; exploit.py implements the full attack chain using only Python standard library modules (argparse, urllib, cookiejar, json, time). The script hardcodes DAG_ID = 'pwn', generates a unique logical_date for each run, maintains cookies across redirects, and includes a custom redirect handler that rewrites OAuth redirects from 127.0.0.1 or localhost to the target host so the attacker can complete the flow remotely. Main exploit capabilities: (1) initiate OAuth login at /auth/login/azure; (2) follow redirect chain and preserve cookies; (3) recover the _token JWT cookie after login; (4) POST to /api/v2/dags/pwn/dagRuns with JSON containing conf.cmd; and (5) execute either an arbitrary shell command or a generated bash reverse shell. The exploit is operational rather than a mere detector because it performs authentication bypass and attempts real code execution. It is not framework-based and appears to be a purpose-built PoC for this Airflow vulnerability.
Repository is a standalone proof-of-concept for CVE-2026-59243, a JWT signature verification bypass in Apache Airflow's FAB Auth Manager Azure AD OAuth path. The core issue described is that affected Airflow code defaults verify_signature to False and decodes id_token values with signature verification disabled, enabling pre-auth identity forgery if an attacker can inject a JWT into the OAuth callback flow. The repo contains documentation in English and Korean, a one-line patch diff showing the upstream fix (False -> True), a Bash advisory-monitoring script unrelated to exploitation, and a self-contained Dockerized PoC under poc/. The PoC consists of a Flask server (poc/server.py) that intentionally reproduces the vulnerable behavior by accepting any JWT via /oauth/callback and /admin using jwt.decode(..., options={"verify_signature": False}), an exploit script (poc/exploit_airflow_jwt.py) that forges an alg:none JWT with Admin role claims and uses it to authenticate and access the admin endpoint, plus Dockerfile/docker-compose/run.sh to build and run the demo locally on 127.0.0.1:5002. Main exploit capability: forge arbitrary identities and roles, including Admin, without possessing signing keys. This is an actual exploit PoC rather than a detector, and while the payload is basic and hardcoded, it is functional and operational.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.