Executive brief
Keycloak, an open-source identity and access management solution, contains a security flaw in how it enforces client policies. An attacker can bypass restrictions intended to block the Resource Owner Password Credentials (ROPC) grant, allowing them to obtain security tokens even when specifically prohibited by administrators. This could lead to unauthorized access to user accounts and sensitive information disclosure.
Technical details
A vulnerability exists in Keycloak's Client Policies within the `org.keycloak.protocol.oidc` component. When security restrictions are enforced using condition providers such as client-type, client-roles, client-attributes, or client-scopes, the `reject-ropc-grant` executor is silently bypassed. This allows a remote, unauthenticated attacker to successfully perform a Resource Owner Password Credentials (ROPC) grant even if a policy is explicitly configured to block it. The flaw stems from improper handling of insufficient permissions or privileges (CWE-280). A fix is available in Keycloak version 26.6.3 and corresponding Red Hat builds.
Affected products
- Keycloak Keycloak >= 26.5.0, < 26.6.3
- Keycloak Keycloak <= 26.4.7
- Red Hat Red Hat build of Keycloak 26.6, 26.4
Timeline
- 2026-05-28: disclosed: Initial disclosure and NVD publication
- 2026-05-28: advisory: GHSA-33j3-g875-37rp published
- 2026-06-10: patched: Red Hat released security advisory RHSA-2026:25098 for Keycloak 26.6.3