Impact
The vulnerability is an access control flaw (CWE‑841) where the token redemption handler in Keycloak Services does not enforce the brute‑force lockout checks that are applied during the CIBA initiation step. Because of this omission, an attacker who already possesses valid client credentials can launch a CIBA authentication request before a user’s account is locked, have the user approve the request, and then redeem tokens after the lockout has been triggered. The attacker thereby obtains unauthorised access and refresh tokens for the locked account, effectively bypassing the intended lockout mechanism.
Affected Systems
Affected vendors and products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific vulnerability‑affected release is listed, so all supported versions of these products should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
With a CVSS score of 4.3 the flaw is classified as moderate severity, and an EPSS score of < 1 % indicates a low likelihood of exploitation at present. The vulnerability is not in the CISA KEV catalog. Exploitation requires the attacker to have legitimate client credentials, initiate a CIBA flow before the account lockout, and obtain the user’s approval. While the attack conditions are non‑trivial, successful exploitation allows full impersonation of the locked user and access to all resources the user could normally obtain.
OpenCVE Enrichment