Junglewise Threat Intelligence

CVE-2026-89298: Keycloak Dynamic Client Registration information disclosure

CVE-2026-89298 · Severity: medium · CVSS 4.9 · Published 2026-09-11

Technologies: Red Hat Keycloak. Vendors: Red Hat.

Executive brief

Keycloak is an open-source identity and access management system used to control user authentication and authorization across applications. A flaw in its client registration service leaks confidential client secrets in cleartext to read-only administrators, allowing them to impersonate clients and escalate their privileges beyond their intended access level.

Technical details

The vulnerability is an information disclosure flaw (CWE-200) in the Dynamic Client Registration GET endpoint. When a user with the view-clients administrative role accesses the endpoint to retrieve client details, the service fails to mask the confidential client secret and returns it in cleartext. Attack vector is network-based, requires high-level privileges (view-clients role), and does not require user interaction. Successful exploitation allows retrieval of plaintext secrets for confidential clients, enabling client impersonation and privilege escalation within the Keycloak realm. Mitigation is not currently available per Red Hat Product Security.

Affected products

  • Red Hat Keycloak <UNKNOWN>

Timeline

  • 2026-09-11: disclosed
  • other: CVE-2026-89298 assigned

References