Description
A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout.
Published: 2026-10-08
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Persistent offline tokens after session termination
Action: Assess Impact
AI Analysis

Impact

An error in the OIDC Dynamic Client Registration component of Keycloak causes the backchannel logout offline token revocation setting to be omitted from serialization responses, and a client performing a standard update silently disables this setting. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout, allowing continued access to protected resources. The flaw is a missing authorization control (CWE-862) that permits an attacker to keep previously issued tokens alive beyond their intended lifecycle.

Affected Systems

The vulnerability affects Red Hat’s Build of Keycloak and Red Hat Single Sign‑On 7. No specific version ranges are listed, so any deployment of these products that uses OIDC dynamic client registration could be impacted.

Risk and Exploitability

With a CVSS score of 4.3, the technical severity is moderate; however the EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating current awareness is limited. The likely attack vector is via the DCR endpoint, which client applications normally use to register or update themselves. An attacker who can trigger or observe a client update can silence the revocation setting without needing elevated privileges, potentially allowing them to keep an offline token alive for replay or persistence attacks. Because no official fix or workaround is currently available, the risk remains present until a remediation is released or the configuration is hard‑wired to prevent automatic disabling of the revocation flag.

Generated by OpenCVE AI on October 8, 2026 at 17:18 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Explicitly verify that the backchannel logout offline token revocation setting is enabled for all clients in your Keycloak deployment, and make the setting immutable in client configuration.
  • Disallow automatic client updates via the DCR endpoint, or apply updates manually after reviewing that the revocation preference remains unchanged.
  • Deploy monitoring or a revocation script to detect and revoke offline tokens that persist beyond authorized session termination events, ensuring session integrity is maintained.

Generated by OpenCVE AI on October 8, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout.
Title Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline token revocation
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T17:41:13.905Z

Reserved: 2026-10-08T13:50:01.978Z

Link: CVE-2026-107623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:46.017

Modified: 2026-10-08T15:17:46.017

Link: CVE-2026-107623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:30:17Z

Weaknesses