CRITICAL
9.1 CVE-2026-76186 Published 16 Sept 2026
Airflow 3.3+ Keycloak Auth Bypass
Worried this affects your website?
Apache Airflow 3.3 and later is affected by a vulnerability in the Keycloak authentication manager.
Airflow takes the user's identity from the signed session token but uses unauthenticated cookies for Keycloak access and refresh tokens, allowing an attacker to pair a valid Airflow login with another user's Keycloak tokens.
This results in unauthorized access using the foreign token's privileges while the session identity remains the attacker's own account.
- Affected: Airflow 3.3 and later with Keycloak auth manager
- Mitigation: Upgrade apache-airflow-providers-keycloak to version 0.10.0 or later
Reference: CVE-2026-76186 on NVD
← Back to Security News