Vulnerability in Apache Airflow's Keycloak Provider Allows Unauthorized Access
CVE-2026-76187
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-76187?
The Keycloak provider in Apache Airflow contains a vulnerability where its unauthenticated token endpoint incorrectly accepts client-credentials grants from any confidential client within a shared Keycloak realm. This flaw allows unauthorized applications with valid credentials to gain access to Airflow, obtaining signed session tokens for those applications' service accounts. An attacker only needs credentials for one valid client within the realm, which can lead to significant security risks, especially if resource authorization is not tightly controlled. Users are strongly advised to update to version 0.10.0 or later to mitigate this issue.
Affected Version(s)
Apache Airflow Keycloak provider 0 < 0.10.0