CVE-2026-7571
published 2026-05-19CVE-2026-7571: A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the…
PriorityP340high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.34%
26.6th percentile
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | >= 26.4 < 26.4.12 | 26.4.12 |
| rhbk | keycloak-rhel9-operator | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak: Access token disclosure and implicit flow bypass via forged client data
ghsa·2026-05-19
CVE-2026-7571 [HIGH] CWE-472 Keycloak: Access token disclosure and implicit flow bypass via forged client data
Keycloak: Access token disclosure and implicit flow bypass via forged client data
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.
GHSA
GHSA-hq3p-w4xv-x7vp: A flaw was found in Keycloak
ghsa_unreviewed·2026-05-19
CVE-2026-7571 [HIGH] CWE-472 GHSA-hq3p-w4xv-x7vp: A flaw was found in Keycloak
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.
Red Hat
keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data
vendor_redhat·2026-05-19·CVSS 7.1
CVE-2026-7571 [HIGH] CWE-472 keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data
keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.
Statement: This High severity flaw in Keycloak allows a low-privilege user, with knowledge of user credentials and client ID, to bypass the `implicitFlowEnabled=false` setting. By forging client data durin
No detection rules found.
No public exploits indexed.
2026-05-19
Published