Skip to content
VulniPulse
Advisory severityCritical9.1Apache Software Foundation

Critical [CVE-2026-76186] Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same subject

This critical-severity Apache Software Foundation advisory covers CVE-2026-76186; related products: Apache Airflow Keycloak.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-76186 Source published Source updated

VulniPulse record published Record updated

Related products & platforms
Apache Software FoundationAirflow
Open source advisory

Android app · Google Play

Monitor future Apache Software Foundation CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same subject.

A user who holds any valid Airflow login of their own, together with another subject's Keycloak access or refresh token obtained out of band, can pair the two: Airflow then authorizes requests with the foreign token's privileges while the session identity, audit log and cache keys continue to name the attacker's own account.

The refresh path re-issues an Airflow session token for the original identity carrying the foreign tokens, so the mismatched pairing survives across sessions.

Affects deployments running Airflow 3.3 or later with the Keycloak auth manager. Earlier versions carried the Keycloak tokens inside the signed session token, so the binding existed and was lost when they moved into separate cookies.

Users of apache-airflow-providers-keycloak are recommended to upgrade to version 0.10.0 or later, which binds the cookie-supplied tokens to the session identity.

Affected versions
  • Apache Airflow Keycloak provider before 0.10.0

Official advisory · high-confidence parse· fetched 20 days ago·verify at source

Fixed versions
  • 0.10.0

Official advisory · high-confidence parse· fetched 20 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Users of apache-airflow-providers-keycloak are recommended to upgrade to version 0.10.0 or later, which binds the cookie-supplied tokens to the session identity.

Official advisory · high-confidence parse· fetched 20 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.