PT-2026-93414 · Red Hat+1 · Keycloak+1

·

CVE-2026-76187

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-keycloak versions prior to 0.10.0
Description The unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, rather than restricting it to the client configured for Airflow. Because no allowlist restricts which client IDs may authenticate, credentials from an unrelated application sharing the same realm are accepted as valid Airflow login credentials, allowing Airflow to mint a signed session token for that application's service account. Additionally, the endpoint allows unauthenticated credential guesses against Keycloak using Airflow's identity. This issue affects deployments using the Keycloak auth manager where the realm is shared with other confidential clients. An attacker with valid credentials for any of those clients can gain access to any endpoint that requires authentication, as well as permissions held by that specific service account.
Recommendations Upgrade to version 0.10.0 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76187

Affected Products

Keycloak
Apache Airflow Providers Keycloak