REDHAT-BUG-2545800: Medium severity Red Hat Keycloak vulnerability

Published Oct 5, 2026
·
Updated

A vulnerability was found in Keycloak where the User Session Note mapper (oidc-usersessionmodel-note-mapper) fails to restrict access to sensitive internal session notes. When a user authenticates through an external identity provider (IdP), Keycloak stores the upstream access and refresh tokens as internal user session notes (FEDERATEDACCESSTOKEN and FEDERATEDREFRESHTOKEN). A delegated administrator with manage permissions for an OIDC client can configure a mapper to copy these internal notes into the client's issued tokens. Because the mapper accepts any note name without validation, it allows a client manager to bypass the dedicated broker-token retrieval API and its associated security checks (such as the broker.read-token role). Successful exploitation requires the attacker to have Fine-Grained Admin Permission (FGAP) to manage at least one OIDC client and for the deployment to have session token storage enabled (default in Identity Brokering API v1). An attacker can then observe the tokens issued to their managed application to obtain a victim's upstream bearer tokens, which are directly usable against the external identity provider to access the victim's account information or perform actions on their behalf.

Affected Software

1 affected component
Red Hat Keycloak

Event History

Oct 5, 2026
Data Sourced
via Red Hat·05:33 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments are exposed when users authenticate through an external identity provider, session token storage is enabled, and a delegated administrator can manage at least one OIDC client using Fine-Grained Admin Permission. Session token storage is enabled by default in Identity Brokering API v1.

2

What level of access does an attacker need?

The attacker needs Fine-Grained Admin Permission to manage at least one OIDC client. They can then configure the User Session Note mapper on that client to copy internal session notes into tokens issued to their managed application.

3

What could an attacker obtain through exploitation?

An attacker can obtain a victim's upstream access and refresh tokens from the external identity provider by observing tokens issued to the attacker-managed application. Those bearer tokens can be used directly against the external identity provider to access the victim's account information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203