Security Flaw in OIDC Implementation of Keycloak Affects User Authentication
CVE-2026-105305

5.4MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105305?

A security flaw in the OIDC implementation of Keycloak was identified, particularly within the Device Authorization Grant flow. This flow permits devices with limited input capabilities to secure access tokens. Due to inadequate checks on the minimum authentication level stipulated by client configurations, an attacker with a stolen user password can circumvent essential multi-factor authentication protocols. This vulnerability poses a significant risk, enabling unauthorized access to the Keycloak Admin REST API, thereby compromising overall system security.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ap4sh (Samy Medjahed) and Ethicxz (Eliott Laurie) for reporting this issue.
.