PT-2026-47027 · Unknown+1 · Uds-Identity-Config+1

·

CVE-2026-46389

·

Published

2026-05-12

·

Updated

2026-06-09

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UDS Identity Config versions 0.11.0 through 0.26.0
Description A logic error exists in the client-kubernetes-secret Keycloak client authenticator. This error causes the submitted client secret to be overwritten with the mounted Kubernetes secret before the comparison occurs. An attacker who can access the Keycloak token endpoint and knows a client id using this authenticator can authenticate as that client using any value for the client secret to obtain OAuth2 tokens scoped to the client's service account. If the uds-operator client is targeted, the obtained token can be used to register or modify other clients.
Recommendations Update to version 0.26.1.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07969
CVE-2026-46389
GHSA-8MG2-6588-R4HW

Affected Products

Keycloak
Uds-Identity-Config