Session Note Leakage in Keycloak Identity and Access Management
CVE-2026-105302
5.7MEDIUM
What is CVE-2026-105302?
A flaw in the User Session Note mapper within Keycloak allows for the potential leakage of sensitive internal credentials, including federated access tokens. This occurs when the mapper fails to properly validate session notes, enabling a delegated client administrator to leak a user’s upstream bearer tokens into tokens issued to their managed applications. This vulnerability poses a risk of unauthorized access to user data on external platforms, making it crucial for organizations to assess their Keycloak configurations and implement necessary security measures.
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Yonghwa Lee (Xint by Theori) for reporting this issue.