Impact
The vulnerability lies in the Microsoft account broker’s token‑exchange path within Keycloak. The broker’s tenant restriction, intended to limit sign‑ins to a specific organization, is ignored when exchanging a Microsoft access token. As a result, a bearer token issued for a different tenant can be swapped for a Keycloak token that grants access to the targeted realm. This presents an authentication bypass (CWE‑287) that could allow unauthorized users to read confidential data or perform privileged actions in the realm.
Affected Systems
Affected products include Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Data Grid 8. Version information is not specified; all installations of these products with the Microsoft broker enabled are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The EPSS score of < 1 % shows a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote network access to the token‑exchange endpoint, as the endpoint is exposed to clients that possess a Microsoft token from another tenant. If an attacker can acquire such a token, they could construct a request from a remote location and exchange it for a Keycloak token, enabling unauthorized access to the realm. In environments where the Microsoft broker is enabled and tenant restrictions are relied upon for security, this flaw could have significant confidentiality and integrity impacts.
OpenCVE Enrichment