Description
A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The flaw lies in the dynamic client registration process of Keycloak, where the system fails to filter security‑sensitive client attributes when creating a new client. An attacker who possesses a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to read sensitive identity data, role memberships, and session details from access tokens issued to other applications within the same realm, effectively enabling unauthorized disclosure of protected information.

Affected Systems

The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific version numbers are listed in the advisory, so any deployment of these products may be impacted until an official fix is available.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score is unavailable, suggesting that exploitation likelihood has not been quantified. The vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to possess a valid Initial Access Token, which means the attacker must have some level of access to the system. The attacker can abuse the flaw to gain unauthorized information from tokens belonging to other applications within the same realm. Because the exploitation path depends on an existing privileged token, the overall risk is moderate but the potential impact of the information disclosure is significant.

Generated by OpenCVE AI on October 5, 2026 at 07:22 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Disable or restrict dynamic client registration so that only trusted administrators can create new clients
  • Ensure that Initial Access Tokens are issued only to privileged users and closely monitor token issuance and client registration logs
  • Apply any vendor‑provided patch or update as soon as Red Hat releases a fix for CVE‑2026‑105306

Generated by OpenCVE AI on October 5, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm.
Title Keycloak-services: keycloak-services: token introspection audience bypass via dynamic client registration
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-05T05:56:51.462Z

Reserved: 2026-10-05T05:40:48.473Z

Link: CVE-2026-105306

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T06:16:58.530

Modified: 2026-10-05T06:16:58.530

Link: CVE-2026-105306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T07:30:18Z

Weaknesses