CVE-2026-107121: Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downgrade
A Cleartext Transmission of Sensitive Information vulnerability was found in the keycloak-services component. The issue exists in the SMTP configuration handling where setting starttls=true results in opportunistic TLS rather than mandatory TLS. An active Man-in-the-Middle attacker can strip the STARTTLS capability from the SMTP server response during the EHLO exchange. Because Keycloak does not enforce the upgrade to TLS, it proceeds to fall back to an unencrypted plaintext connection. This allows the attacker to capture SMTP authentication credentials and the full content of email messages transmitted by the server.
Other sources
A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text.
— MITRE
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of Keycloak keycloak-services that use SMTP with starttls=true are exposed when an active attacker can intercept and modify the network traffic between Keycloak and the SMTP server.
What must an attacker do to exploit it?
The attacker must act as a man in the middle during the SMTP EHLO exchange and remove the server's advertised STARTTLS capability. Keycloak then continues over plaintext rather than requiring TLS.
What information can be exposed if exploitation succeeds?
An attacker can capture SMTP authentication credentials and the full contents of email messages sent by the server.
Is simply enabling STARTTLS sufficient protection?
No. In the affected configuration, starttls=true uses opportunistic TLS and does not force an encrypted connection when the STARTTLS negotiation is tampered with.