CVE-2026-37979
published 2026-05-19CVE-2026-37979: A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client…
PriorityP343medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.37%
28.8th percentile
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | >= 26.4 < 26.4.12 | 26.4.12 |
| rhbk | keycloak-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4x37-hw65-52w8: A flaw was found in Keycloak
ghsa_unreviewed·2026-05-19
CVE-2026-37979 [MEDIUM] CWE-284 GHSA-4x37-hw65-52w8: A flaw was found in Keycloak
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.
GHSA
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
ghsa·2026-05-19
CVE-2026-37979 [MEDIUM] CWE-284 Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.
Red Hat
keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
vendor_redhat·2026-05-19·CVSS 6.5
CVE-2026-37979 [MEDIUM] keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.
Statement: Moderate impact: Keycloak's OIDC token introspection endpoint fails to enforce audience validation, allowing a confidential client to retrieve sensitive token claims intended for a different audience. This com
No detection rules found.
No public exploits indexed.
2026-05-19
Published