Token Exchange Vulnerability in Keycloak Affects Google Account Logins
CVE-2026-18214

6.8MEDIUM

What is CVE-2026-18214?

Keycloak is an open-source identity and access management solution that facilitates user authentication via Google accounts. A significant flaw exists in its token exchange mechanism, which fails to enforce domain restrictions when swapping Google tokens for Keycloak tokens. This oversight allows attackers with valid Google accounts from unintended domains to bypass the intended security measures and gain unauthorized access to protected Keycloak realms, potentially leading to unauthorized data exposure and compromise of sensitive user information.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.