Skip to main content

CVE-2026-76186: CWE-565: Reliance on Cookies without Validation and Integrity Checking in a Security Decision in Apache Software Foundation Apache Airflow Keycloak provider

0
High
VulnerabilityCVE-2026-76186cvecve-2026-76186cwe-565
Published: 09/16/2026 (09/16/2026, 09:09:57 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Airflow Keycloak provider

Description

Apache Airflow Keycloak provider versions prior to 0.10.0 have a vulnerability where Keycloak access and refresh tokens are stored in separate, unauthenticated cookies without validation against the signed Airflow session token. This allows an attacker with a valid Airflow login and a foreign Keycloak token to gain unauthorized privileges while maintaining their own session identity. The issue affects Airflow 3.3 or later deployments using the Keycloak auth manager. Upgrading to apache-airflow-providers-keycloak version 0.10.0 or later mitigates this by binding tokens to the session identity.

Affected software

Apache Software Foundation

Apache Airflow Keycloak provider

Affected versions
>=0 <0.10.0
apache-airflow-providers-keycloak
pkg:pypi/apache-airflow-providers-keycloak
Affected versions
>=0 <0.10.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 09:47:09 UTC

Technical Analysis

The Apache Airflow Keycloak provider introduced a security flaw starting with Airflow 3.3 where the Keycloak access and refresh tokens are stored in separate cookies that are not authenticated or validated against the signed Airflow session token. This lack of binding allows an attacker who possesses a valid Airflow login and a foreign Keycloak token (access or refresh) obtained out of band to pair these tokens. As a result, Airflow authorizes requests using the foreign token's privileges, while audit logs and session caches reflect the attacker's own identity, enabling privilege escalation and session persistence across refreshes. Earlier Airflow versions embedded Keycloak tokens inside the signed session token, ensuring proper binding. The vulnerability affects apache-airflow-providers-keycloak versions before 0.10.0. The issue is resolved by upgrading to version 0.10.0 or later, which enforces binding of cookie-supplied tokens to the session identity.

Potential Impact

An attacker with any valid Airflow login and a foreign Keycloak access or refresh token can escalate privileges by pairing their session with the foreign token, gaining unauthorized access rights. The mismatch between session identity and token privileges can persist across session refreshes, potentially allowing unauthorized actions under the guise of the attacker's account. This undermines authorization integrity and audit reliability in affected deployments.

Mitigation Recommendations

Users should upgrade apache-airflow-providers-keycloak to version 0.10.0 or later, which binds the Keycloak tokens to the session identity, preventing token pairing attacks. No other mitigations are indicated. Patch status is confirmed by the vendor advisory recommending this upgrade.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-19T10:41:19.914Z
State
PUBLISHED

Threat ID: 6aaa621555bf5e2cf54c8cd2

Added to database: 09/16/2026, 09:32:05 UTC

Last enriched: 09/16/2026, 09:47:09 UTC

Last updated: 09/16/2026, 09:47:09 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses