漏洞概述 漏洞编号:CVE-2026-9802 漏洞名称:Keycloak: Unauthorized account access via replayed refresh tokens after cluster restart 状态:NEW 报告时间:2026-05-28 04:12 UTC by OSIDB Bzimport 修改时间:2026-05-28 04:43 UTC CC List:10 users (now) 产品:Security Response 组件:vulnerability 版本:unspecified 硬件:All 操作系统:Linux 优先级:medium 严重性:medium 目标里程碑:--- 分配给:Product Security QA联系人:--- 文档联系人:--- URL:--- 白板:--- 依赖项:--- 阻塞项:--- 树视图:depends on / blocked 影响范围 描述:当 启用且使用持久会话存储时,服务器重启会重置内部计时机制。这允许远程攻击者,在之前捕获了用户的刷新令牌后,即使该令牌已被撤销,也可以重放该令牌。成功的利用将授予攻击者对受害者账户的未授权访问,可能导致信息泄露或权限提升。 修复方案 修复版本:--- 关闭版本:--- 环境:--- 最后关闭时间:--- 已冻结:--- 附件 附件名称:(Terms of Use) 描述: 备注 备注:You need to log in before you can comment on or make changes to this bug. 其他信息 隐私政策:Privacy 联系方式:Contact 常见问题:FAQ 法律条款:Legal