Keycloak Authentication Flaw in Apache Airflow by Apache
CVE-2026-76186
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-76186?
The Keycloak provider in Apache Airflow 3.3 and later versions has a critical vulnerability that allows users to exploit mismatched session identities. This occurs because the Keycloak access and refresh tokens are stored in separate, unauthenticated cookies, creating a scenario where a valid user can combine their signed Airflow session token with another user's Keycloak token. As a result, the attacker gains unauthorized access to resources with the privileges of the paired token, while the session identity remains tied to the attacker's own account. This flaw underscores the importance of binding authentication tokens securely to maintain user identity integrity.
Affected Version(s)
Apache Airflow Keycloak provider 0 < 0.10.0