Impact
Keycloak's Level of Authentication enforcement logic contains a flaw that allows a client requiring a higher security level to be served a lower‑level token when a user already has an active session at the lower level. The malformed session re‑evaluation can result in an unauthorized token being issued, enabling access to protected resources that rely on proper authentication assertions. The weakness is a Missing Authorization flaw (CWE‑862), which leads to privilege escalation within the identity broker.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific mitigated versions are listed, so any installation of these products that has not applied a future update or patch may be vulnerable.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is no current evidence of widespread exploitation. The attack likely requires remote interaction with the Keycloak session management interface, and the attacker must target a client that requests a higher authentication level. Based on the description, it is inferred that an attacker could manipulate session cookies or session requests to trigger the downgrade, though no explicit exploitation path is documented.
OpenCVE Enrichment