CVE-2026-76186
CRITICALApache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same subject. A user who holds any valid Airflow login of their own, together with another
- Affected
- <0.10.0
- Fixed in
- not stated
- Weakness
- CWE-565
- Published
- 2026-09-16
- Source
- NVD