Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107604— Keycloak-services: keycloak-services: view-clients role allows retrieval of active client secrets via installation provider endpoints

Quick assessment

Affected
Red Hat Red Hat Build of Keycloak
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Keycloak 身份管理服务在安装提供程序和客户端注册端点中发现了一个安全漏洞。具有只读 view-clients 角色的域管理员可以访问任何机密客户端的活动主密钥,这通常应是受限操作。该暴露的密钥可用于伪装客户端,并未经授权地访问其关联的服务账户权限。

CVSS 4.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107604

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: view-clients role allows retrieval of active client secrets via installation provider endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the installation provider and client registration endpoints of the Keycloak identity management service. A realm administrator with only the read-only view-clients role can access the active primary secret of any confidential client, which should normally be restricted. This exposed secret can be used to impersonate the client and gain unauthorized access to its associated service account permissions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-107604

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107604

请登录查看更多情报信息。

Other References for CVE-2026-107604 (2)

Same Patch Batch · Red Hat · 2026-10-08 · 7 CVEs total

CVE-2026-93017 7.7 HIGH Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and
CVE-2026-107466 6.1 MEDIUM Flatpak-builder: local file exfiltration via `file
CVE-2026-107445 5.4 MEDIUM Rubygem-katello: katello flatpak remote repositories api cross-organization authorization
CVE-2026-107565 5.1 MEDIUM Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow dat
CVE-2026-107623 4.3 MEDIUM Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline
CVE-2026-107444 4.3 MEDIUM Rubygem-katello: katello docker tags repositories api cross-organization authorization byp

IV. Related Vulnerabilities

V. Comments for CVE-2026-107604

No comments yet


Leave a comment