JWT Bearer Authorization Flaw in Red Hat Build of Keycloak
CVE-2026-79652

5.9MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
25 August 2026

What is CVE-2026-79652?

A vulnerability has been identified in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This issue arises due to inadequate validation of client consent requirements when issuing access tokens. An authenticated attacker possessing valid client credentials can exploit this flaw to bypass the necessary consent checks, thereby gaining unauthorized access to user accounts at consent-gated clients. This compromises the integrity and privacy of user data, highlighting the necessity for timely remediation and robust security practices.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Johan Wahyudi for reporting this issue.
.