Description
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.
Published: 2026-07-31
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Microsoft account broker’s token‑exchange path within Keycloak. The broker’s tenant restriction, intended to limit sign‑ins to a specific organization, is ignored when exchanging a Microsoft access token. As a result, a bearer token issued for a different tenant can be swapped for a Keycloak token that grants access to the targeted realm. This presents an authentication bypass (CWE‑287) that could allow unauthorized users to read confidential data or perform privileged actions in the realm.

Affected Systems

Affected products include Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Data Grid 8. Version information is not specified; all installations of these products with the Microsoft broker enabled are potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. The EPSS score of < 1 % shows a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote network access to the token‑exchange endpoint, as the endpoint is exposed to clients that possess a Microsoft token from another tenant. If an attacker can acquire such a token, they could construct a request from a remote location and exchange it for a Keycloak token, enabling unauthorized access to the realm. In environments where the Microsoft broker is enabled and tenant restrictions are relied upon for security, this flaw could have significant confidentiality and integrity impacts.

Generated by OpenCVE AI on August 4, 2026 at 22:30 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply any available vendor patch or update Red Hat Keycloak products once an official fix is released.
  • Disable the Keycloak token exchange feature for the realm if disabling the feature is possible and does not disrupt critical services.
  • Verify that Microsoft tenant restrictions are enforced in the realm’s OAuth2 configuration and log all token exchange attempts.
  • Monitor logs for abnormal token issuance or use of Microsoft tokens from disallowed tenants.

Generated by OpenCVE AI on August 4, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 31 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.
Title Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
Weaknesses CWE-287
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-31T11:00:46.327Z

Reserved: 2026-07-29T08:47:14.946Z

Link: CVE-2026-18215

cve-icon Vulnrichment

Updated: 2026-07-31T11:00:39.774Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T08:16:27.893

Modified: 2026-08-07T18:11:31.577

Link: CVE-2026-18215

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-28T12:12:27Z

Links: CVE-2026-18215 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:45:03Z

Weaknesses