PT-2026-93413 · Apache · Apache Airflow Providers Keycloak

·

CVE-2026-76186

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow Keycloak provider versions 3.3 and later
Description The Keycloak auth manager retrieves a user's identity from a signed Airflow session token but obtains Keycloak access and refresh tokens from separate, unauthenticated cookies. Because the system fails to verify that both the session identity and the tokens refer to the same subject, an attacker with a valid Airflow login and another user's Keycloak tokens can pair them. This allows the attacker to perform requests with the privileges of the foreign token while the session identity, audit logs, and cache keys still reflect the attacker's account. Additionally, the refresh process re-issues a session token that maintains this mismatched pairing across sessions.
Recommendations Upgrade apache-airflow-providers-keycloak to version 0.10.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76186

Affected Products

Apache Airflow Providers Keycloak