Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15943

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires high administrative privileges to exploit. Successful exploitation allows an attacker to rebind and capture an OIDC client secret by modifying identity provider configuration fields. The vulnerability's root cause is the unconditional reuse of masked secrets during configuration updates without verifying if sensitive endpoint fields have changed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesAffected
Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Affected
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1288
https://bugzilla.redhat.com/show_bug.cgi?id=2501270keycloak-services: keycloak-services: OIDC IdP update reuses masked client secret after token URL change

EPSS

Процентиль: 10%
0.00199
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 1 месяца назад

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.

CVSS3: 5.5
debian
около 1 месяца назад

A flaw was found in the Keycloak keycloak-services component, which ha ...

CVSS3: 5.5
github
около 1 месяца назад

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.

EPSS

Процентиль: 10%
0.00199
Низкий

5.5 Medium

CVSS3