cbcvebase.
CVE-2026-7571
published 2026-05-19

CVE-2026-7571: A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the…

PriorityP340high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.34%
26.6th percentile
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.

Affected

2 ranges
VendorProductVersion rangeFixed in
redhatbuild_of_keycloak>= 26.4 < 26.4.1226.4.12
rhbkkeycloak-rhel9-operator

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.