CVE-2026-105306: Keycloak-services: keycloak-services: token introspection audience bypass via dynamic client registration
A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm.
Other sources
A vulnerability was found in Keycloak where the Dynamic Client Registration (DCR) flow does not properly filter sensitive client attributes. Specifically, a registrant using an Initial Access Token can set the internal attribute allow.token.introspection.without.audience.check during the registration process. This attribute disables the mandatory audience verification on the token introspection endpoint. To exploit this flaw, an attacker must possess a valid Initial Access Token for a realm where DCR is enabled. By registering a malicious client with this attribute, the attacker can then use that client's credentials to introspect any active access token they have obtained or intercepted from other clients in the same realm. Successful exploitation results in the disclosure of the full claim set of the token, including user identity, roles, scopes, and session IDs, regardless of whether the introspecting client was the intended audience. This is a bypass of the security controls introduced to fix CVE-2026-37979.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to exploitation?
A realm is exposed when Dynamic Client Registration is enabled and an attacker can obtain a valid Initial Access Token for that realm.
What must an attacker do after obtaining an Initial Access Token?
The attacker registers a client with the internal allow.token.introspection.without.audience.check attribute set. They can then use the malicious client’s credentials to bypass audience verification at the token introspection endpoint.
What is the impact of a successful bypass?
The attacker can introspect active access tokens issued to other applications in the same realm and view sensitive identity information, roles, and session details.