Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7571

Опубликовано: 19 мая 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.

Отчет

This High severity flaw in Keycloak allows a low-privilege user, with knowledge of user credentials and client ID, to bypass the implicitFlowEnabled=false setting. By forging client data during a session restart, an attacker can obtain an implicit access token, potentially exposing it in URL query strings if response_mode=query is also forged. This bypass undermines a critical security control intended to prevent implicit flow, leading to unauthorized access to sensitive tokens.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the Keycloak authentication endpoint to trusted clients and networks. Implement firewall rules to control inbound connections to the Keycloak service ports, thereby reducing the attack surface and limiting who can initiate authentication flows and potentially exploit the implicit flow bypass. If the Keycloak service is reloaded or restarted, ensure these network restrictions remain in effect.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-472
https://bugzilla.redhat.com/show_bug.cgi?id=2464263keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data

EPSS

Процентиль: 26%
0.00344
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
2 месяца назад

A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.

CVSS3: 7.1
debian
2 месяца назад

A flaw was found in Keycloak. A low-privilege user, with knowledge of ...

CVSS3: 7.1
github
2 месяца назад

Keycloak: Access token disclosure and implicit flow bypass via forged client data

EPSS

Процентиль: 26%
0.00344
Низкий

7.1 High

CVSS3