Impact
A flaw in Keycloak's OpenID Connect token refresh flow causes the server to issue new access tokens without verifying that the requested audience client is still enabled. An attacker or compromised application that holds a valid refresh token can request new tokens for a client that has been disabled, thereby bypassing administrative controls that rely on the client’s disabled state and potentially granting illicit access to protected resources. The vulnerability arises from missing authorization checks, identified as CWE-862.
Affected Systems
The weakness affects Red Hat’s Build of Keycloak and Red Hat Single Sign‑On 7. No specific patch or version information is listed, so any installation running these products without an as‑yet‑released fix is vulnerable.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower current exploitation likelihood. Although the flaw requires possession of a valid refresh token – typically a credential that an attacker may obtain through phishing or credential compromise – the attack is remotely reachable and could allow privilege escalation on resource servers that accept offline JWT validation.
OpenCVE Enrichment