CVE-2026-105302: Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access tokens
A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a delegated client administrator to leak a user's upstream bearer tokens into the tokens issued to their managed application, potentially leading to unauthorized access to the user's data on external platforms.
Other sources
A vulnerability was found in Keycloak where the User Session Note mapper (oidc-usersessionmodel-note-mapper) fails to restrict access to sensitive internal session notes. When a user authenticates through an external identity provider (IdP), Keycloak stores the upstream access and refresh tokens as internal user session notes (FEDERATEDACCESSTOKEN and FEDERATEDREFRESHTOKEN). A delegated administrator with manage permissions for an OIDC client can configure a mapper to copy these internal notes into the client's issued tokens. Because the mapper accepts any note name without validation, it allows a client manager to bypass the dedicated broker-token retrieval API and its associated security checks (such as the broker.read-token role). Successful exploitation requires the attacker to have Fine-Grained Admin Permission (FGAP) to manage at least one OIDC client and for the deployment to have session token storage enabled (default in Identity Brokering API v1). An attacker can then observe the tokens issued to their managed application to obtain a victim's upstream bearer tokens, which are directly usable against the external identity provider to access the victim's account information or perform actions on their behalf.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A delegated administrator who has manage permissions for an OIDC client can configure the User Session Note mapper to copy sensitive internal session notes into tokens issued for that client. Exploitation also depends on users authenticating through an external identity provider.
What information could be exposed?
The mapper can expose upstream access tokens and refresh tokens stored by Keycloak as the FEDERATED_ACCESS_TOKEN and FEDERATED_REFRESH_TOKEN session notes. A managed application's issued tokens could then contain bearer credentials for the external identity provider.
Does exploitation require user interaction?
Yes. The supplied severity vector indicates user interaction is required. The described scenario involves a user authenticating through an external identity provider, after which the sensitive federated tokens are stored in the user session.
How can an administrator identify potential exposure?
Review OIDC client configurations managed by delegated administrators for User Session Note mappers, particularly mappings that request FEDERATED_ACCESS_TOKEN or FEDERATED_REFRESH_TOKEN. Also identify clients whose users authenticate through external identity providers, as those sessions may contain the affected internal notes.