PT-2026-93413 · Apache · Apache Airflow Providers Keycloak
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow Keycloak provider versions 3.3 and later
Description
The Keycloak auth manager retrieves a user's identity from a signed Airflow session token but obtains Keycloak access and refresh tokens from separate, unauthenticated cookies. Because the system fails to verify that both the session identity and the tokens refer to the same subject, an attacker with a valid Airflow login and another user's Keycloak tokens can pair them. This allows the attacker to perform requests with the privileges of the foreign token while the session identity, audit logs, and cache keys still reflect the attacker's account. Additionally, the refresh process re-issues a session token that maintains this mismatched pairing across sessions.
Recommendations
Upgrade apache-airflow-providers-keycloak to version 0.10.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Providers Keycloak