CVE-2026-105305: Keycloak-services: keycloak-services: device authorization grant bypasses per-client minimum.acr.value enforcement
A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client configuration. This allows an attacker who has stolen a user's password to bypass mandatory multi-factor authentication and gain unauthorized access to the Keycloak Admin REST API.
Other sources
A flaw was found in the org.keycloak.protocol.oidc package of Keycloak. The OAuth 2.0 Device Authorization Grant flow does not correctly enforce the per-client minimum.acr.value setting. While the standard Authorization Code flow properly requires multi-factor authentication (MFA) when this setting is present, the Device Authorization flow allows authentication to complete at a lower Level of Assurance (LoA 1, password only). The root cause is a missing validation step in the device grant code path to ensure the resulting authentication context class reference (ACR) meets the client's configured minimum. An attacker with knowledge of a user's primary credentials can exploit this to bypass MFA requirements. Successful exploitation allows the attacker to obtain a valid access token with the client's scoped roles and use it to perform unauthorized actions via the Keycloak Admin REST API, such as managing users or modifying realm configurations.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What conditions are required for exploitation?
The affected client must use the OAuth 2.0 Device Authorization Grant flow and have a per-client minimum.acr.value requirement configured. The attacker must know a user's primary credentials, allowing password-only authentication at LoA 1.
Is the standard Authorization Code flow affected in the same way?
No. The provided information states that the standard Authorization Code flow properly requires MFA when minimum.acr.value is configured; the missing validation is in the Device Authorization Grant path.
What access could an attacker obtain through this bypass?
An attacker who bypasses the MFA requirement can gain unauthorized access to the Keycloak Admin REST API.