CVE-2025-12150
published 2026-02-27CVE-2025-12150: A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register…
PriorityP415low3.1CVSS 3.1
AVNACHPRNUIRSUCNILAN
EPSS
0.20%
10.3th percentile
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| keycloak | keycloak | < 26.4.4 | 26.4.4 |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| redhat | build_of_keycloak | < 26.4.4 | 26.4.4 |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_msrc7.4HIGH
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass
vendor_redhat·2025-10-28·CVSS 3.1
CVE-2025-12150 [LOW] CWE-347 org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass
org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direc
Microsoft
It was found that samba before 4.4.16 4.5.x before 4.5.14 and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-
vendor_msrc·2018-07-10·CVSS 7.4
CVE-2017-12150 [HIGH] CWE-300 It was found that samba before 4.4.16 4.5.x before 4.5.14 and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-
It was found that samba before 4.4.16 4.5.x before 4.5.14 and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact
OSV
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
osv·2026-02-27
CVE-2025-12150 [LOW] Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
GHSA
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
ghsa·2026-02-27
CVE-2025-12150 [LOW] CWE-347 Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6856 keycloak: keycloak: acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration
bugzilla·2026-04-21·CVSS 3.1
CVE-2026-6856 [LOW] CVE-2026-6856 keycloak: keycloak: acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration
CVE-2026-6856 keycloak: keycloak: acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration
WebAuthn AAGUID policy bypass via packed self-attestation. Similar to CVE-2025-12150. When direct attestation is requested but the authenticator sends self-attestation (no x5c), the AAGUID is unverified, allowing bypass of the acceptable AAGUID allowlist.
Affects RHBK 26.4 and Keycloak 26.6. Patch in progress.
Wiz
CVE-2025-12150 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.1
CVE-2025-12150 [LOW] CVE-2025-12150 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12150 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
Source : NVD
## 3.1
Score
Published February 27, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected p
https://access.redhat.com/errata/RHSA-2025:21370https://access.redhat.com/errata/RHSA-2025:21371https://access.redhat.com/errata/RHSA-2025:22088https://access.redhat.com/errata/RHSA-2025:22089https://access.redhat.com/security/cve/CVE-2025-12150https://bugzilla.redhat.com/show_bug.cgi?id=2406192https://github.com/keycloak/keycloak/issues/43723
2026-02-27
Published