Token Exchange Vulnerability in Keycloak Affects Google Account Logins
CVE-2026-18214
6.8MEDIUM
What is CVE-2026-18214?
Keycloak is an open-source identity and access management solution that facilitates user authentication via Google accounts. A significant flaw exists in its token exchange mechanism, which fails to enforce domain restrictions when swapping Google tokens for Keycloak tokens. This oversight allows attackers with valid Google accounts from unintended domains to bypass the intended security measures and gain unauthorized access to protected Keycloak realms, potentially leading to unauthorized data exposure and compromise of sensitive user information.
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.