External risk intelligence

Apache Airflow Keycloak Provider Allows Unrestricted Client Authentication

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-76187

The vulnerability affects an Apache Airflow authentication provider. Airflow web interfaces and their associated API/authentication endpoints are commonly deployed as network-accessible services to facilitate remote access for users and automation workflows, placing them frequently at the edge of internal or public network segments.

Authentication Bypass

Apache Airflow Providers Keycloak

before 0.10.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the Apache Airflow Keycloak provider that could allow unauthorized access to your Airflow environment. If your Keycloak realm is shared with other applications, an attacker could use the credentials of any confidential client within that realm to log into Airflow, potentially gaining access to sensitive data or systems.

  • Unauthorized access to Airflow via shared credentials.
  • Matters for environments sharing Keycloak realms.
  • Confirm relevance and exposure of Airflow Keycloak integration.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by using the valid credentials of any confidential client registered in the same Keycloak realm as Airflow, even if that client is not intended for Airflow. This allows the attacker to authenticate as that client's service account and obtain a signed session token, granting them the same access rights as that service account. The endpoint also permits unauthenticated credential guessing against Keycloak under Airflow's identity.

  • Unauthenticated access to shared realm.
  • Client credentials grant token issuance.
  • Access as unrelated service account.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to impersonate any service account within a shared Keycloak realm by using valid credentials for an unrelated confidential client. When supported by the advisory, this could lead to unauthorized access to Airflow resources based on the permissions of the impersonated service account, and potentially allow unauthenticated credential guessing against Keycloak under Airflow's identity.

  • Service account credentials.
  • Valid unrelated client credentials.
  • Unauthorized resource access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts deployments of the Apache Airflow Keycloak provider when the Keycloak realm is shared with other confidential clients. The primary responsibility for addressing this likely falls to the platform or application team managing the Airflow instance, in coordination with the security or network team responsible for the Keycloak infrastructure. The first practical step is to identify all Airflow instances using the Keycloak auth manager, confirm their exposure and criticality, and then ascertain the specific Airflow and Keycloak client configurations to plan remediation.

  • Platform and app teams own the issue.
  • Verify shared realm and client credentials.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the apache-airflow-providers-keycloak component?

This software component is a plugin for Apache Airflow that enables integration with Keycloak, an open-source identity and access management system. Organizations use this provider to manage Airflow user authentication and authorization centrally through Keycloak rather than maintaining separate credentials for their data pipeline workflows.

What does CWE-287 mean for CVE-2026-76187?

CWE-287 refers to improper authentication. In this CVE, the vulnerability occurs because the provider fails to verify which specific client is attempting to log in. Instead of only accepting the client ID configured for Airflow, the system incorrectly trusts any confidential client registered within the same shared Keycloak realm to authenticate.

Does this vulnerability trigger if I use a dedicated Keycloak realm?

No. The trigger requires a shared Keycloak realm environment. If your Airflow deployment uses a dedicated, isolated realm that does not host other confidential applications, the vulnerability cannot be triggered because there are no unrelated client credentials for an attacker to leverage against the Airflow login endpoint.

How does Halo Surface Signal describe the risk?

Halo Surface Signal identifies this as a likely risk because Apache Airflow interfaces and their authentication endpoints are often positioned at the edge of network segments to support remote access. This placement increases the potential for unauthorized external actors to reach the authentication service if it is exposed to the network.

How do I start addressing this issue?

Begin by auditing your Airflow instances to confirm if they use the Keycloak auth manager and verify if the underlying Keycloak realm is shared with other applications. Once identified, prioritize updating the apache-airflow-providers-keycloak package to version 0.10.0 or later, which correctly restricts authentication to the specific client intended for Airflow.

References