Junglewise Threat Intelligence

CVE-2026-97846: Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requ

CVE-2026-97846 · Severity: medium · CVSS 6.8 · Published 2026-09-25

Executive brief

Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard Token Exchange V2 feature does not check for this certificate. This allows an attacker with stolen client credentials to obtain a standard, unrestricted token that bypasses these security protections.

References