SMTP Email Configuration Vulnerability in Keycloak by Red Hat
CVE-2026-107121

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107121?

A flaw exists in the SMTP email configuration of the Keycloak services component. When the STARTTLS option is activated, Keycloak does not enforce a strict encrypted connection, leading to a fallback to unencrypted communication if the encryption request is altered. This vulnerability can be exploited by attackers who intercept network traffic, potentially allowing them to capture sensitive email credentials and message content in plain text.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli of Trail of Bits in collaboration with OpenAI for reporting this issue.
.