Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107623— Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline token revocation

Quick assessment

Affected
Red Hat Red Hat Build of Keycloak
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Keycloak 的 OIDC 动态客户端注册(DCR)组件中发现了一个缺陷。该组件在响应序列化过程中存在一个 bug,导致“反向通道注销时的离线令牌吊销”设置未被包含在响应中。当客户端执行标准更新操作时,由于缺少该信息,此设置会被静默禁用。因此,即使用户会话通过反向通道注销被终止,离线令牌仍可能保持有效。

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 3

VendorProduct Version RangeStatus
Red Hat Red Hat Build of Keycloak any affected
any affected
Red Hat Red Hat Single Sign-On 7 any unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107623

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline token revocation
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-107623

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107623

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-107623 (2)

Same Patch Batch · Red Hat · 2026-10-08 · 9 CVEs total

CVE-2026-89091 8.8 HIGH Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows a
CVE-2026-93017 7.7 HIGH Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and
CVE-2026-107466 6.1 MEDIUM Flatpak-builder: local file exfiltration via `file
CVE-2026-107651 5.5 MEDIUM Eog: eog: arbitrary code execution via heap buffer overflow in png metadata reader
CVE-2026-107445 5.4 MEDIUM Rubygem-katello: katello flatpak remote repositories api cross-organization authorization
CVE-2026-107565 5.1 MEDIUM Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow dat
CVE-2026-107604 4.9 MEDIUM Keycloak-services: keycloak-services: view-clients role allows retrieval of active client
CVE-2026-107444 4.3 MEDIUM Rubygem-katello: katello: katello: katello docker tags repositories api cross-organization

IV. Related Vulnerabilities

V. Comments for CVE-2026-107623

No comments yet


Leave a comment