Description
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Published: 2026-07-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in the keycloak-services component causes OAuth 2.0 authorization codes to lack proper binding to the client that requested them. If an attacker intercepts an authorization code, they can alter it so that a different client can redeem it, thereby obtaining access tokens that represent the victim’s identity. This can enable impersonation and subsequent unauthorized access to protected resources, compromising confidentiality and integrity of the victim’s accounts.

Affected Systems

The vulnerability affects Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7, and Red Hat Data Grid 8. All affected products use the keycloak-services component, and the issue applies to the specific build identified in the Red Hat catalog. No specific patch version is listed, so any installation of these products from the time of the advisory is potentially impacted.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity risk. The EPSS score of < 1% suggests that exploitation is unlikely in the short term. The vulnerability is not currently listed in the CISA KEV catalog, so no publicly known exploits have been reported. The attack vector involves intercepting an authorization code, which typically requires network-level access or a compromised network component. However, the absence of a binding allows an attacker to modify the code after interception, reducing the complexity required once the code is in hand.

Generated by OpenCVE AI on August 4, 2026 at 07:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of the affected Red Hat products or install the vendor’s latest security update for keycloak-services
  • Ensure that all authorization traffic is transmitted over TLS and monitor for unusual interception patterns
  • Configure the authorization service to enforce binding between authorization codes and client identifiers, and validate this binding on code exchange; if a binding check is not available, consider is applied

Generated by OpenCVE AI on August 4, 2026 at 07:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-384
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Title Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-22T18:20:30.767Z

Reserved: 2026-07-17T14:00:35.799Z

Link: CVE-2026-16089

cve-icon Vulnrichment

Updated: 2026-07-22T18:19:55.361Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-17T12:17:39Z

Links: CVE-2026-16089 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:15:03Z

Weaknesses