Executive brief
A security flaw was identified in Red Hat Build of Keycloak, an identity and access management solution. The vulnerability allows an attacker to intercept a user's login code and redirect it to their own malicious application. If successful, the attacker could obtain access tokens for the victim's identity, potentially leading to unauthorized access to user data and account impersonation.
Technical details
A vulnerability exists in the keycloak-services component where OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. The authorization code payload fails to persist the issuing client identifier, and the token endpoint relies on a mutable component of the code string to identify the client session. An attacker with a registered client in the same realm can intercept a victim's authorization code, rewrite the client identifier, and redeem it at the token endpoint. This allows the attacker to obtain access tokens associated with the victim's identity for the attacker-controlled client. Exploitation requires the attacker to have network access to intercept the code and a valid client registration.
Affected products
- Red Hat Red Hat Build of Keycloak unspecified
Timeline
- 2026-07-17: disclosed: CVE published and reported to Red Hat Bugzilla