Description
A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is still enabled before issuing a new access token. This allows an application with an existing refresh token to continue obtaining valid access tokens for a disabled client, potentially bypassing administrative access controls for resource servers that rely on offline JWT validation.
Published: 2026-09-19
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access via continued token issuance for disabled clients
Action: Apply patch
AI Analysis

Impact

A flaw in Keycloak's OpenID Connect token refresh flow causes the server to issue new access tokens without verifying that the requested audience client is still enabled. An attacker or compromised application that holds a valid refresh token can request new tokens for a client that has been disabled, thereby bypassing administrative controls that rely on the client’s disabled state and potentially granting illicit access to protected resources. The vulnerability arises from missing authorization checks, identified as CWE-862.

Affected Systems

The weakness affects Red Hat’s Build of Keycloak and Red Hat Single Sign‑On 7. No specific patch or version information is listed, so any installation running these products without an as‑yet‑released fix is vulnerable.

Risk and Exploitability

The CVSS score of 4.2 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower current exploitation likelihood. Although the flaw requires possession of a valid refresh token – typically a credential that an attacker may obtain through phishing or credential compromise – the attack is remotely reachable and could allow privilege escalation on resource servers that accept offline JWT validation.

Generated by OpenCVE AI on September 19, 2026 at 23:32 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the official Keycloak patch released by Red Hat as soon as it becomes available.
  • Revoke all active refresh tokens for any clients that have been disabled to prevent further token issuance.
  • Configure resource servers to validate the enabled state of an audience client when accepting access tokens, rejecting tokens that reference disabled clients.
  • Review the Red Hat CNA statement: no effective workaround is currently available or existing options do not meet security criteria.

Generated by OpenCVE AI on September 19, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat single Sign-on

Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is still enabled before issuing a new access token. This allows an application with an existing refresh token to continue obtaining valid access tokens for a disabled client, potentially bypassing administrative access controls for resource servers that rely on offline JWT validation.
Title Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled audience clients
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T15:57:50.987Z

Reserved: 2026-09-19T14:00:00.818Z

Link: CVE-2026-93999

cve-icon Vulnrichment

Updated: 2026-09-22T15:57:41.973Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-19T15:17:08.627

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-93999

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T01:00:50Z

Links: CVE-2026-93999 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:30Z

Weaknesses