Flaw in Keycloak's Client Registration Endpoints Exposes Sensitive Secrets
CVE-2026-107604

4.9MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107604?

A security flaw exists within the Keycloak identity management service concerning its installation provider and client registration endpoints. This vulnerability enables a realm administrator with only the read-only view-clients role to access the active primary secret of any confidential client. Such access should be restricted to higher privilege roles. The compromised secret can be leveraged to impersonate the client, thus obtaining unauthorized access to the associated service account permissions, which poses a significant security risk.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank WHS4th Team TokenManiZo for reporting this issue.
.