Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40948

19
FAUCET Score

OVERVIEW CVE-2026-40948 is an authentication bypass vulnerability in apache-airflow-providers-keycloak that stems from improper OAuth 2.0 implementation. The vulnerable component fails to generate or validate the state parameter during login flows and does not implement PKCE (Proof Key for Code Exchange), security controls fundamental to OAuth 2.0. An attacker with legitimate access to the same Keycloak realm can exploit this flaw to perform login-CSRF or session fixation attacks, tricking victims into logging into attacker-controlled Airflow sessions where subsequently stored credentials can be harvested. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.4 (MEDIUM) with a network-based attack vector requiring minimal complexity and user interaction to trigger. The impact is limited to confidentiality and integrity breach with no availability impact. The low EPSS score of 0.000070000 suggests minimal prevalence in real-world exploitation relative to other CVEs. The Faucet risk score of 32/100 indicates moderate organizational risk, particularly in environments where Keycloak and Airflow integration stores sensitive connection credentials. EXPLOITATION STATUS There is no evidence of active exploitation, as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities catalog and inactive status on the Hot List. No public exploit code is documented. The relatively low EPSS and risk scores suggest limited community attention. However, organizations using apache-airflow-providers-keycloak should prioritize upgrading to version 0.7.0 or later to close this authentication bypass vector before threat actors develop operational exploits.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.0.1, < 0.7.0CPE match
cpe:2.3:a:apache:apache-airflow-providers-keycloak:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 25th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: apache-airflow-providers-keycloakFixed in: 0.7.0
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

pipGHSA-5w6h-pjw6-wvc6medium

apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation

Apr 18, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10953.htmlLOW

CVE-2026-40948: Apache Airflow Keycloak Provider: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager

Apr 17, 2026

References

openwall.com / lists/oss-security/2026/04/17/14
Mailing ListThird Party Advisory
github.com / apache/airflow/pull/64114
Issue TrackingPatch
lists.apache.org / thread/kc0odpr70hbqhdb9ksnz42fkqz2xld9q
Mailing ListVendor Advisory