External risk intelligence

Apache Airflow Keycloak Provider Token Mismatch Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-76186

Apache Airflow is commonly deployed as a web-based workflow orchestration platform that often includes a web UI and API. As an identity management integration, the Keycloak authentication component is typically exposed to the network to facilitate user access, making the web interface and its associated authentication handlers reachable in many standard deployment environments.

Apache Airflow Providers Keycloak

before 0.10.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in the Apache Airflow Keycloak authentication provider, specifically impacting deployments using version 3.3 or later. The issue allows an attacker to potentially gain unauthorized privileges by pairing a valid session with a mismatched authentication token, impacting system integrity and access controls. The main concern is confirming relevance and exposure.

  • Mismatched tokens allow unauthorized access.
  • Affects Airflow 3.3+ with Keycloak.
  • Confirm if your Airflow deployment is impacted.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by first gaining their own valid Airflow login. Then, they would need to obtain a Keycloak access or refresh token belonging to another user through an out-of-band method. By pairing their existing Airflow session with this foreign token, the attacker can then make requests authenticated with the privileges of the other user, impacting the integrity and confidentiality of the system.

  • Attacker has own Airflow login.
  • Pairs foreign token with Airflow session.
  • Unauthorized actions with another user's privileges.

Live Threat

Current exploitation, exposure, and threat context

When the Apache Airflow Keycloak provider is running with specific configurations, an attacker could impersonate another user by combining their own valid Airflow session with a foreign Keycloak token. This could allow them to perform actions or access data as the other user, as the system would authorize requests using the foreign token's privileges while logging them under the attacker's account.

  • Unauthorized access to user data or system functions.
  • Foreign tokens obtained out-of-band.
  • Impersonation and unauthorized actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Apache Airflow deployments using the Keycloak authentication manager with versions 3.3 and later. The primary responsibility for addressing this issue likely falls to the Platform or Infrastructure Team managing Airflow, in coordination with Security Teams for exposure assessment and Vendor Management if the Keycloak integration is managed by a third party. The first practical move is to identify all Airflow instances utilizing the Keycloak provider, confirm their network reachability, and ascertain their business criticality to prioritize remediation efforts.

  • Platform/Infrastructure team owns remediation.
  • Verify Keycloak auth manager reachability.
  • Plan upgrade to version 0.10.0.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the apache-airflow-providers-keycloak component?

Apache Airflow is a platform used to programmatically author, schedule, and monitor workflows. The Keycloak provider is an integration component that allows Airflow to delegate user authentication and identity management to Keycloak, a centralized identity server. In versions 3.3 and later, this provider manages how users log into the Airflow web interface and API by handling the exchange of identity tokens between the two systems.

What does CVE-2026-76186 mean by a token mismatch?

This vulnerability, classified as CWE-565 (Relying on Cookies without Validation), occurs because the system fails to verify that the user's session token and the Keycloak authorization tokens refer to the same identity. Because they are handled as separate, unlinked cookies, the application processes requests using the privileges associated with a foreign Keycloak token while maintaining the session identity of the original user.

How is this vulnerability triggered by an attacker?

An attacker must already have a valid Airflow login of their own and must separately obtain a Keycloak access or refresh token belonging to another user through some external, out-of-band means. Simply interacting with the Airflow interface without a stolen token does not trigger this issue. The bug specifically requires the attacker to successfully inject or pair this foreign token with their own existing session cookies.

How relevant is this CVE to my Airflow deployment?

Halo Surface Signal indicates this issue is highly relevant because Airflow is typically deployed as a web-based platform with its authentication handlers directly reachable over the network. If your instance uses the Keycloak auth manager on version 3.3 or higher, it is potentially susceptible to unauthorized privilege escalation. You should prioritize internal visibility checks to see if your authentication interfaces are exposed to broader network segments.

What are the first steps to fix this vulnerability?

The primary action is to update the apache-airflow-providers-keycloak package to version 0.10.0 or later. This update introduces binding logic that cryptographically ties the cookie-supplied tokens to the specific user session identity, preventing the mismatch. Before updating, identify all running Airflow instances that utilize the Keycloak integration and schedule the version upgrade as part of your standard maintenance cycle.

References