Token Redemption Flaw in Keycloak Affects Identity and Access Management
CVE-2026-88770

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88770?

A critical flaw in the Device Authorization Grant flow of Keycloak allows attackers to exploit the token redemption process. This vulnerability arises when the system fails to verify if a user account has been locked due to brute-force attempts. An attacker with an active session for a locked account can bypass these security measures, successfully completing the device login process. This enables unauthorized access to security tokens, granting the attacker continued access to the account despite it being restricted.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Sunil Tripathy for reporting this issue.
.