vulnerability in Keycloak mTLS feature allowing unauthorized token access
CVE-2026-97846
6.8MEDIUM
What is CVE-2026-97846?
Keycloak's mTLS holder-of-key binding feature is designed to ensure that tokens can only be used by the original client that requested them. However, a flaw has been identified in the new Standard Token Exchange V2 feature which neglects to validate the client's digital certificate. This oversight permits attackers with compromised client credentials to exploit the system and acquire a standard, unrestricted token, effectively bypassing the intended security controls.