Back

MEDIUM

Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2

Published Sep 18, 2026

Description

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having a Low impact. This flaw is limited to improper parameter formatting when the application server forwards a token to an external Identity Provider (IdP) for verification. Under specific conditions, a malformed token can inject additional data into that outgoing verification request. The application server relies on the external IdP to decide whether a token is valid, and standard IdPs automatically reject malformed or invalid requests. Additionally, role and access permissions are strictly enforced inside the application server after the identity check is completed. Because an attacker cannot force an authentication bypass using a standard IdP setup, the overall security risk is minimal and the real-world impact remains low.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 18, 2026
Updated Sep 25, 2026
Reserved Sep 4, 2026

CISA Vulnrichment

Updated Sep 18, 2026

NVD

Status Awaiting Analysis
Modified Sep 18, 2026

Red Hat

Severity Low
Public date Sep 18, 2026
Bugzilla 2483140

ENISA EUVD

Assigner redhat
Published Sep 18, 2026
Updated Sep 25, 2026

GitHub

No data