REDHAT-BUG-2523347: Medium severity Keycloak Keycloak vulnerability

Published Aug 25, 2026
·
Updated

A Missing Authorization flaw (CWE-862) was identified in the JWT Bearer authorization grant (urn:ietf:params:oauth:grant-type:jwt-bearer) in Keycloak. The vulnerability exists in the JWTAuthorizationGrantType.process function, which fails to verify the client.isConsentRequired flag or check for a stored UserConsentModel before issuing an access token. While other user-facing grants like Resource Owner Password Credentials (ROPC) explicitly refuse consent-required clients, and interactive grants verify stored consent, the JWT Bearer grant bypasses these checks entirely. To exploit this flaw, an attacker must have access to a confidential client credentials and a valid JWT assertion for a target user signed by an allow-listed Identity Provider (IdP). Successful exploitation allows an attacker to: Obtain a valid access token for a target user without their consent.

Access protected resources and APIs on behalf of the user.

Bypass administrative security policies intended to gate client access behind explicit user approval.

Affected Software

1 affected component
Keycloak Keycloak

Event History

Aug 25, 2026
Data Sourced
via Red Hat·10:44 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What conditions are required to exploit this issue?

An attacker needs credentials for a confidential client and a valid JWT assertion for the target user. The assertion must be signed by an allow-listed identity provider.

2

Which deployments are exposed?

Deployments using the JWT Bearer authorization grant are exposed when a confidential client requires user consent and the environment accepts JWT assertions from an allow-listed identity provider. The flaw is specific to the JWT Bearer grant's missing consent validation.

3

What is the impact if exploitation succeeds?

An attacker can obtain an access token for the target user without that user's consent. The token can be used to access protected resources and APIs as that user, bypassing policies that require explicit user approval for client access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203