CVE-2026-107121: Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downgrade

Published Oct 7, 2026
·
Updated

A Cleartext Transmission of Sensitive Information vulnerability was found in the keycloak-services component. The issue exists in the SMTP configuration handling where setting starttls=true results in opportunistic TLS rather than mandatory TLS. An active Man-in-the-Middle attacker can strip the STARTTLS capability from the SMTP server response during the EHLO exchange. Because Keycloak does not enforce the upgrade to TLS, it proceeds to fall back to an unencrypted plaintext connection. This allows the attacker to capture SMTP authentication credentials and the full content of email messages transmitted by the server.

Other sources

A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text.

— MITRE

Affected Software

1 affected component
Keycloak keycloak-services

Event History

Oct 7, 2026
Data Sourced
via Red Hat·07:27 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments of Keycloak keycloak-services that use SMTP with starttls=true are exposed when an active attacker can intercept and modify the network traffic between Keycloak and the SMTP server.

2

What must an attacker do to exploit it?

The attacker must act as a man in the middle during the SMTP EHLO exchange and remove the server's advertised STARTTLS capability. Keycloak then continues over plaintext rather than requiring TLS.

3

What information can be exposed if exploitation succeeds?

An attacker can capture SMTP authentication credentials and the full contents of email messages sent by the server.

4

Is simply enabling STARTTLS sufficient protection?

No. In the affected configuration, starttls=true uses opportunistic TLS and does not force an encrypted connection when the STARTTLS negotiation is tampered with.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203