CVE-2026-76186
CVE-2026-76186 is a critical-severity vulnerability in Apache Apache-airflow-providers-keycloak with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-565.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- EPSS exploit prediction: 1% (56th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-565
- Affected product: Apache Apache-airflow-providers-keycloak
- Published:
- Last modified:
Description
Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same subject. A user who holds any valid Airflow login of their own, together with another subject's Keycloak access or refresh token obtained out of band, can pair the two: Airflow then authorizes requests with the foreign token's privileges while the session identity, audit log and cache keys continue to name the attacker's own account. The refresh path re-issues an Airflow session token for the original identity carrying the foreign tokens, so the mismatched pairing survives across sessions. Affects deployments running Airflow 3.3 or later with the Keycloak auth manager. Earlier versions carried the Keycloak tokens inside the signed session token, so the binding existed and was lost when they moved into separate cookies. Users of apache-airflow-providers-keycloak are recommended to upgrade to version 0.10.0 or later, which binds the cookie-supplied tokens to the session identity.
Frequently asked questions
- What is CVE-2026-76186?
- Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same subject. A user who holds any valid Airflow login of their own, together with another subject's Keycloak access or refresh token obtained out of band, can pair the two: Airflow then authorizes requests with the foreign token's privileges while the session identity, audit log and cache keys continue to name the attacker's own account. The refresh path re-issues an Airflow session token for the original identity carrying the foreign tokens, so the mismatched pairing survives across sessions. Affects deployments running Airflow 3.3 or later with the Keycloak auth manager. Earlier versions carried the Keycloak tokens inside the signed session token, so the binding existed and was lost when they moved into separate cookies. Users of apache-airflow-providers-keycloak are recommended to upgrade to version 0.10.0 or later, which binds the cookie-supplied tokens to the session identity.
- How severe is CVE-2026-76186?
- CVE-2026-76186 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-76186 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (56th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-76186?
- CVE-2026-76186 affects Apache Apache-airflow-providers-keycloak. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-76186?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-76186 published?
- CVE-2026-76186 was published on 2026-09-16 and last updated on 2026-09-18.
References
- https://github.com/apache/airflow/pull/72207
- https://lists.apache.org/thread/5cqh5ojl3718ogb0q1dcd9vdr47z7gp3
- https://lists.apache.org/thread/[email protected]
- http://www.openwall.com/lists/oss-security/2026/09/15/8
Affected products (1)
- cpe:2.3:a:apache:apache-airflow-providers-keycloak:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Apache-airflow-providers-keycloak
- CVE-2026-76187 — Critical (CVSS 9.8): Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any…
- CVE-2026-40948 — Medium (CVSS 5.4): The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0…
All CVEs affecting Apache Apache-airflow-providers-keycloak →
Other CWE-565 vulnerabilities
- CVE-2023-41084 — Critical (CVSS 10.0): Session management within the web application is incorrect and allows attackers to steal session cookies to perform a…
- CVE-2026-85181 — Critical (CVSS 9.8): CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing…
- CVE-2014-125112 — Critical (CVSS 9.8): Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code…
- CVE-2022-50926 — Critical (CVSS 9.8): WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to…
- CVE-2025-65212 — Critical (CVSS 9.8): An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the…
- CVE-2025-14440 — Critical (CVSS 9.8): The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,…