CVE-2026-107623Medium· 4.3▾ SunlitA flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105306Medium· 6.5A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server
CVE-2026-97311Medium· 4.3A flaw was found in the Admin REST API of Keycloak, an identity and access management solution
CVE-2026-97176Medium· 4.2A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution
CVE-2026-97177Medium· 6.6A flaw was found in the user update mechanism of the Keycloak Admin REST API
CVE-2026-96446Medium· 4.2A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak
CVE-2026-107604Medium· 4.9A flaw was found in the installation provider and client registration endpoints of the Keycloak identity management service