Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2
Published Sep 18, 2026
4.2
MEDIUMCVSS 3.1
EPSS 0.28%
Description
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Data Grid 8 | affected | |
| Red Hat | Red Hat Fuse 7 | affected | |
| Red Hat | Red Hat Single Sign-On 7 | affected |
No data.
No data.
Red Hat JBoss Enterprise Application Platform 7
wildfly-elytron-realm-token
Not affected
Red Hat JBoss Enterprise Application Platform 8
wildfly-elytron-realm-token
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
wildfly-elytron-realm-token
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 7 | wildfly-elytron-realm-token | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | wildfly-elytron-realm-token | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | wildfly-elytron-realm-token | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having a Low impact. This flaw is limited to improper parameter formatting when the application server forwards a token to an external Identity Provider (IdP) for verification. Under specific conditions, a malformed token can inject additional data into that outgoing verification request. The application server relies on the external IdP to decide whether a token is valid, and standard IdPs automatically reject malformed or invalid requests. Additionally, role and access permissions are strictly enforced inside the application server after the identity check is completed. Because an attacker cannot force an authentication bypass using a standard IdP setup, the overall security risk is minimal and the real-world impact remains low.
References (9)
- https://access.redhat.com/errata/RHSA-2026:70228 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70229 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70230 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70277 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-85511 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2483140 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82946 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85511
- https://www.cve.org/CVERecord?id=CVE-2026-85511
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:70228 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:70229 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:70230 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:70277 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-85511 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2483140 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82946 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-85511 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-85511 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data