CVE-2026-9705: Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an authenticated user account or user interaction?
The CVSS vector indicates no privileges and no user interaction are required. However, the described attack requires the attacker to possess a previously issued Registration Access Token for the target client.
Which products are identified as affected?
The affected software list includes Red Hat Build of Keycloak and Keycloak.
What is the assessed severity and attack exposure?
This issue is rated medium with a CVSS score of 6.5. The vector identifies network-based exploitation with low attack complexity, confidentiality and integrity impact, and no availability impact.