Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16093

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 5.4

Описание

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that the attacker must already possess valid client credentials to perform the bypass. Successful exploitation allows an attacker to bypass mandatory signed-JWT assertion policies by providing unsigned headers. The vulnerability's root cause is insufficient validation of the client assertion parameters and authentication method within the client policy executor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesAffected
Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Affected
Red Hat Data Grid 8keycloak-servicesFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesFix deferred
Red Hat Single Sign-On 7keycloak-servicesFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2501729keycloak-services: keycloak-services: Required signed-JWT assertion policy can be bypassed with unsigned assertion headers

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 месяца назад

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.

CVSS3: 5.4
debian
около 1 месяца назад

Keycloak provides a mechanism called Client Policies to enforce securi ...

CVSS3: 5.4
github
около 1 месяца назад

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.

5.4 Medium

CVSS3