Security Flaw in Keycloak Login Theme Component
CVE-2026-107889

5.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107889?

A security vulnerability has been identified in the login theme rendering component of Keycloak. This flaw enables a bypass of the security filter intended to cleanse user inputs. Consequently, this permits a realm administrator to embed harmful scripts into display fields. When users access the login page, these malicious scripts may execute in their browsers, creating risks of data exposure and session interference.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Mohammed LACHHAB for reporting this issue.
.