Token Exchange Vulnerability in Keycloak by Red Hat
CVE-2026-18215
6.8MEDIUM
What is CVE-2026-18215?
Keycloak allows users to authenticate using Microsoft accounts while restricting access to designated organizations. However, a security flaw enables this restriction to be bypassed during the token exchange process. An attacker possessing a valid Microsoft token, even from an unrelated organization, may gain unforeseen access to sensitive realms within Keycloak. This could lead to unauthorized actions or data exposure, posing significant risks to user and organizational security.
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.