Executive brief
Red Hat Keycloak is an identity and access management system used to control user authentication and access to enterprise applications. A flaw in its device login flow allows an attacker with an existing active session to obtain new access tokens even after their account has been locked due to failed login attempts. This bypasses security protections designed to stop account takeovers and can allow attackers to maintain unauthorized access to locked accounts.
Technical details
The vulnerability is an authentication bypass in the Device Authorization Grant token redemption code path. The root cause is a missing brute-force account status check: the token redemption process fails to verify whether a user account is locked before issuing new security tokens. Attack precondition: the attacker must have an active SSO browser session established for the target account prior to the account lockout. When the account is subsequently locked due to brute-force protection, the attacker can exploit the device authorization flow to bypass this protection and obtain valid tokens. The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) with a CVSS v3.1 score of 6.5 (Network/Low complexity/Low privileges required).
Affected products
- Red Hat Keycloak
Timeline
- 2026-09-10: disclosed