CVE-2026-105302Medium· 5.7▾ SunlitA flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, suc…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a delegated client administrator to leak a user's upstream bearer tokens into the tokens issued to their managed application, potentially leading to unauthorized access to the user's data on external platforms.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105306Medium· 6.5A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server
CVE-2026-105301Medium· 4.0A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management
CVE-2026-103884Medium· 6.5A flaw was found in the X.509 client certificate authenticator of Keycloak
CVE-2026-96448Medium· 6.6A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution
CVE-2026-97846Medium· 6.8Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate
CVE-2026-97311Medium· 4.3A flaw was found in the Admin REST API of Keycloak, an identity and access management solution