CRITICAL 9.1 CVE-2026-76186 Published 16 Sept 2026

Airflow 3.3+ Keycloak Auth Bypass

Worried this affects your website?

Apache Airflow 3.3 and later is affected by a vulnerability in the Keycloak authentication manager.

Airflow takes the user's identity from the signed session token but uses unauthenticated cookies for Keycloak access and refresh tokens, allowing an attacker to pair a valid Airflow login with another user's Keycloak tokens.

This results in unauthorized access using the foreign token's privileges while the session identity remains the attacker's own account.

  • Affected: Airflow 3.3 and later with Keycloak auth manager
  • Mitigation: Upgrade apache-airflow-providers-keycloak to version 0.10.0 or later

Reference: CVE-2026-76186 on NVD

← Back to Security News