Incorrect Authorization Affecting apache-airflow-providers-keycloak package, versions [,0.10.0rc1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.98% (61st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSKEYCLOAK-19882864
  • published17 Sept 2026
  • disclosed16 Sept 2026
  • creditUnknown

Introduced: 16 Sep 2026

NewCVE-2026-76187  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-keycloak to version 0.10.0rc1 or higher.

Overview

apache-airflow-providers-keycloak is a Provider package apache-airflow-providers-keycloak for Apache Airflow

Affected versions of this package are vulnerable to Incorrect Authorization in the unauthenticated token endpoint, which accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not just the intended one. An attacker can obtain a valid session token by supplying credentials for any confidential client within the shared realm.

Note: This is only exploitable if the Keycloak realm is shared with other confidential clients and the attacker possesses valid credentials for one of those clients.

CVSS Base Scores

version 4.0
version 3.1