# CVE-2026-46745

## Summary

- **CVE ID:** CVE-2026-46745
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-90
- **Published:** May 25, 2026
- **Last Modified:** May 26, 2026

## Description

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.

## Affected Products

- Apache Software Foundation — Apache Airflow FAB provider (0)

## References

- [CNA](https://github.com/apache/airflow/pull/66417)
- [CNA](https://lists.apache.org/thread/dvfy0bs181xwsrjrd3y5c55ztbzm8yhh)
- [CVE](http://www.openwall.com/lists/oss-security/2026/05/24/10)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._