CVE-2026-105305Medium· 5.4▾ SunlitA flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client configuration. This allows an attacker who has stolen a user's password to bypass mandatory multi-factor authentication and gain unauthorized access to the Keycloak Admin REST API.
keycloak-services (all versions)rhbk/keycloak-rhel9 (all versions)keycloak-servicesRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97846Medium· 6.8Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate
CVE-2026-96445Medium· 6.8A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution
CVE-2026-105306Medium· 6.5A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server
CVE-2026-105301Medium· 4.0A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management
CVE-2026-105302Medium· 5.7A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution
CVE-2026-103884Medium· 6.5A flaw was found in the X.509 client certificate authenticator of Keycloak