Junglewise Threat Intelligence

CVE-2026-7571: Red Hat Keycloak implicit flow bypass and token disclosure

CVE-2026-7571 · Severity: high · CVSS 7.1 · Published 2026-05-19

Technologies: Red Hat build of Keycloak, Red Hat build of Keycloak, org.keycloak:keycloak-services (Maven), Keycloak. Vendors: Red Hat, Maven, Keycloak.

Executive brief

Keycloak is an open-source identity and access management solution used to secure modern applications and services. A vulnerability was found where a user with valid credentials can bypass security settings to obtain unauthorized access tokens. This could allow an attacker to gain higher-level access than intended or lead to the exposure of sensitive session data in server logs and web headers.

Technical details

A flaw exists in Keycloak's handling of OpenID Connect (OIDC) flows, specifically categorized as CWE-472 (External Control of Assumed-Immutable Web Parameter). A low-privileged attacker with valid credentials and knowledge of a client ID can manipulate client data during a session restart to bypass controls that disable the implicit flow. This allows the attacker to obtain an access token that should otherwise be restricted. Furthermore, the vulnerability can cause these tokens to be leaked in server logs, proxy logs, and HTTP Referrer headers. The issue is fixed in Keycloak version 26.6.2 and Red Hat build of Keycloak 26.4.12.

Affected products

  • Keycloak Keycloak < 26.6.2
  • Red Hat Red Hat build of Keycloak 26.4.x < 26.4.12

Timeline

  • 2026-04-30: other: Reported to Red Hat Bugzilla
  • 2026-05-19: disclosed: Initial public disclosure and NVD publication
  • 2026-05-20: patched: Red Hat released security advisories RHSA-2026:19597 and RHSA-2026:19596
  • 2026-06-04: advisory: GitHub Advisory reviewed and updated

References

Related threats