Flaw in Keycloak's Client Registration Endpoints Exposes Sensitive Secrets
CVE-2026-107604
4.9MEDIUM
What is CVE-2026-107604?
A security flaw exists within the Keycloak identity management service concerning its installation provider and client registration endpoints. This vulnerability enables a realm administrator with only the read-only view-clients role to access the active primary secret of any confidential client. Such access should be restricted to higher privilege roles. The compromised secret can be leveraged to impersonate the client, thus obtaining unauthorized access to the associated service account permissions, which poses a significant security risk.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank WHS4th Team TokenManiZo for reporting this issue.