Executive brief
Keycloak is an open-source identity and access management platform that controls user authentication and authorization. A flaw in its Kerberos authentication provider allows attackers on the same network to impersonate the authentication server and bypass login verification, gaining unauthorized access to user accounts without needing valid credentials.
Technical details
The Kerberos federation provider in Keycloak fails to verify the identity of the Key Distribution Center (KDC) by requesting a server ticket when Kerberos password authentication is used without SPNEGO. This is a cryptographic signature verification flaw (CWE-347) exploitable by adjacent network attackers with no privileges or user interaction required. An attacker can spoof the KDC to intercept and bypass authentication, leading to unauthorized access and data compromise.
Affected products
- Red Hat Keycloak <unknown
Timeline
- 2026-09-22: disclosed