Keycloak(一款开源的身份和访问管理解决方案)的OIDC协议实现中存在一个缺陷。该问题发生在令牌刷新过程中,当服务器从存储的客户端ID恢复所请求的受众(audience)时触发。Keycloak在签发新的访问令牌之前,未能验证目标受众的客户端是否仍处于启用状态。这使得拥有现有刷新令牌的应用程序能够持续为已禁用的客户端获取有效的访问令牌,从而可能绕过依赖离线JWT验证的资源服务器的管理访问控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94000 | 6.6 MEDIUM | Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to re |
| CVE-2026-94001 | 6.5 MEDIUM | Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-passwo |
No comments yet