CVE-2025-14559: Org.keycloak/keycloak-services: keycloak keycloak-services: business logic flaw allows unauthorized token issuance for disabled users

Published Dec 12, 2025
·
Updated

A business logic vulnerability exists in the Token Exchange implementation within the keycloak-services component. When a privileged client invokes the token exchange flow, Keycloak correctly validates the client but fails to validate whether the target “requestedsubject” user is enabled. This omission allows issuance of access and refresh tokens for users whose accounts have been explicitly disabled. An internal client with the impersonation permission can therefore resurrect “zombie accounts,” obtaining tokens for former employees or banned users despite account deactivation. This flaw enables unauthorized use of previously revoked privileges and relies solely on the presence of an internal high-privileged client, requiring no user interaction or direct authentication by the disabled user.

Other sources

A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privileged client invokes the token exchange flow.

MITRE

Affected Software

2 affected components
maven/org.keycloak/keycloak-services
maven/org.keycloak:keycloak-services<=26.5.1

Event History

Dec 12, 2025
Data Sourced
via Red Hat·09:55 AM
DescriptionSeverityAffected Software
Jan 21, 2026
CVE Published
via MITRE·06:13 AM
Data Sourced
via MITRE·06:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 AM
Data Sourced
via GitHub·09:31 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-14559?

CVE-2025-14559 is classified as a business logic flaw that allows unauthorized token issuance for disabled users, which poses a significant security risk.

2

How does CVE-2025-14559 affect Keycloak services?

CVE-2025-14559 affects the Token Exchange implementation in Keycloak services, potentially allowing privileged clients to issue tokens for disabled accounts.

3

How do I fix CVE-2025-14559?

To remediate CVE-2025-14559, it is recommended to upgrade to Keycloak services version 26.5.2 or later, where the vulnerability is addressed.

4

Who is affected by CVE-2025-14559?

Any organization using affected versions of Keycloak services is at risk of CVE-2025-14559 if they rely on the Token Exchange functionality.

5

What are the potential impacts of CVE-2025-14559?

The potential impacts of CVE-2025-14559 include unauthorized access to sensitive resources by issuing tokens for disabled user accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203