Keycloak Authentication Flaw in Apache Airflow by Apache
CVE-2026-76186

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-76186?

The Keycloak provider in Apache Airflow 3.3 and later versions has a critical vulnerability that allows users to exploit mismatched session identities. This occurs because the Keycloak access and refresh tokens are stored in separate, unauthenticated cookies, creating a scenario where a valid user can combine their signed Airflow session token with another user's Keycloak token. As a result, the attacker gains unauthorized access to resources with the privileges of the paired token, while the session identity remains tied to the attacker's own account. This flaw underscores the importance of binding authentication tokens securely to maintain user identity integrity.

Affected Version(s)

Apache Airflow Keycloak provider 0 < 0.10.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security Scans
Jarek Potiuk
.