Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce consentrequired
Published Aug 25, 2026
5.9
MEDIUMCVSS 3.1
EPSS 0.34%
Description
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client requires user consent before issuing a token. This allows an authenticated attacker with valid client credentials and a trusted identity provider assertion to bypass the consent requirement and obtain unauthorized access to a user account at a consent-gated client.
Affected products
No data.
No data.
No data.
Red Hat build of Keycloak 26.6
rhbk/keycloak-operator-bundle:26.6.7-3
Fixed · RHSA-2026:68277
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9-operator:26.6-20
Fixed · RHSA-2026:68277
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9:26.6-20
Fixed · RHSA-2026:68277
Red Hat build of Keycloak 26.6.7
keycloak-services
Fixed · RHSA-2026:68278
Red Hat build of Keycloak 26.6.7
keycloak/rhbk-openshift-rhel9
Fixed · RHSA-2026:68278
Red Hat build of Keycloak 26.6.7
rhbk/keycloak-rhel9
Fixed · RHSA-2026:68278
Red Hat Single Sign-On 7
keycloak-services
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle:26.6.7-3 | Fixed | RHSA-2026:68277 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9-operator:26.6-20 | Fixed | RHSA-2026:68277 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9:26.6-20 | Fixed | RHSA-2026:68277 |
| Red Hat build of Keycloak 26.6.7 | keycloak-services | Fixed | RHSA-2026:68278 |
| Red Hat build of Keycloak 26.6.7 | keycloak/rhbk-openshift-rhel9 | Fixed | RHSA-2026:68278 |
| Red Hat build of Keycloak 26.6.7 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:68278 |
| Red Hat Single Sign-On 7 | keycloak-services | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Red Hat statement
The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires a specific non-default client configuration and the possession of valid client credentials and a trusted IdP assertion. Successful exploitation allows an attacker to bypass user consent requirements and obtain an access token for a target user. The vulnerability's root cause is a missing authorization check in the JWT Bearer grant implementation that fails to honor the consentRequired configuration flag.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 25, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.34% (0.00339) | 25.03th | v5 (v2026.06.15) |
| Aug 26, 2026 | 0.17% (0.00170) | 6.43th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/errata/RHSA-2026:68277 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68278 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-79652 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2523347 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-79652
- https://www.cve.org/CVERecord?id=CVE-2026-79652
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:68277 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:68278 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-79652 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2523347 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-79652 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-79652 |
Change history (0)
No recorded changes yet.