Session Note Leakage in Keycloak Identity and Access Management
CVE-2026-105302

5.7MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105302?

A flaw in the User Session Note mapper within Keycloak allows for the potential leakage of sensitive internal credentials, including federated access tokens. This occurs when the mapper fails to properly validate session notes, enabling a delegated client administrator to leak a user’s upstream bearer tokens into tokens issued to their managed applications. This vulnerability poses a risk of unauthorized access to user data on external platforms, making it crucial for organizations to assess their Keycloak configurations and implement necessary security measures.

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Yonghwa Lee (Xint by Theori) for reporting this issue.
.