Executive brief
Keycloak is an open-source identity and access management solution used to secure modern applications and services. A security flaw in its client registration service allows an attacker who has an old registration token to re-activate a client account that an administrator had previously disabled. This could allow the attacker to reset security credentials and gain unauthorized access to protected data or systems.
Technical details
A vulnerability classified as Insufficient Session Expiration (CWE-613) exists in Keycloak's client registration service. A remote attacker possessing a previously issued Registration Access Token (RAT) can bypass administrative security controls to re-enable a client that was explicitly disabled by an administrator. By re-enabling the client, the attacker can reset the client's secret, potentially regaining privileged API access and leading to unauthorized information disclosure or integrity compromise. The attack is reachable over the network and requires the possession of a valid RAT but no other specific privileges.
Affected products
- Red Hat Red Hat Build of Keycloak
- Keycloak Keycloak
Timeline
- 2026-05-27: other: Bug reported to Red Hat Bugzilla
- 2026-06-25: disclosed: CVE published to NVD