Keycloak: keycloak: access token disclosure and implicit flow bypass via forged client data
Published May 19, 2026
7.1
HIGHCVSS 3.1
EPSS 0.42%
Description
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.
Affected products
No data.
- ≥ 26.4 · < 26.4.12
No data.
Red Hat build of Keycloak 26.4
rhbk/keycloak-operator-bundle:26.4.12-1
Fixed · RHSA-2026:19597
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9-operator:26.4-17
Fixed · RHSA-2026:19597
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9:26.4-17
Fixed · RHSA-2026:19597
Red Hat build of Keycloak 26.4.12
rhbk/keycloak-rhel9-operator
Fixed · RHSA-2026:19596
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.12-1 | Fixed | RHSA-2026:19597 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator:26.4-17 | Fixed | RHSA-2026:19597 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9:26.4-17 | Fixed | RHSA-2026:19597 |
| Red Hat build of Keycloak 26.4.12 | rhbk/keycloak-rhel9-operator | Fixed | RHSA-2026:19596 |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, restrict network access to the Keycloak authentication endpoint to trusted clients and networks. Implement firewall rules to control inbound connections to the Keycloak service ports, thereby reducing the attack surface and limiting who can initiate authentication flows and potentially exploit the implicit flow bypass. If the Keycloak service is reloaded or restarted, ensure these network restrictions remain in effect.
Red Hat statement
This High severity flaw in Keycloak allows a low-privilege user, with knowledge of user credentials and client ID, to bypass the `implicitFlowEnabled=false` setting. By forging client data during a session restart, an attacker can obtain an implicit access token, potentially exposing it in URL query strings if `response_mode=query` is also forged. This bypass undermines a critical security control intended to prevent implicit flow, leading to unauthorized access to sensitive tokens.
Red Hat mitigation
To mitigate this issue, restrict network access to the Keycloak authentication endpoint to trusted clients and networks. Implement firewall rules to control inbound connections to the Keycloak service ports, thereby reducing the attack surface and limiting who can initiate authentication flows and potentially exploit the implicit flow bypass. If the Keycloak service is reloaded or restarted, ensure these network restrictions remain in effect.
References (12)
- https://access.redhat.com/errata/RHSA-2026:19596 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:19597 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-7571 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2464263 issue-trackingx_refsource_REDHATVendor AdvisoryIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30888 Advisory
- https://github.com/advisories/GHSA-hq3p-w4xv-x7vp Advisory
- https://github.com/keycloak/keycloak/commit/56bbfa3d8abccf39df787ae73e044a75aba1da13
- https://github.com/keycloak/keycloak/issues/49110
- https://github.com/keycloak/keycloak/pull/49120
- https://github.com/keycloak/keycloak/releases/tag/26.6.2
- https://nvd.nist.gov/vuln/detail/CVE-2026-7571
- https://www.cve.org/CVERecord?id=CVE-2026-7571
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:19596 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2026:19597 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-7571 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464263 | issue-trackingx_refsource_REDHATVendor AdvisoryIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30888 | Advisory | |
| https://github.com/advisories/GHSA-hq3p-w4xv-x7vp | Advisory | |
| https://github.com/keycloak/keycloak/commit/56bbfa3d8abccf39df787ae73e044a75aba1da13 | ||
| https://github.com/keycloak/keycloak/issues/49110 | ||
| https://github.com/keycloak/keycloak/pull/49120 | ||
| https://github.com/keycloak/keycloak/releases/tag/26.6.2 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2026-7571 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-7571 |
Change history (0)
No recorded changes yet.