PT-2026-60799 · Red Hat · Keycloak
CVE-2026-16103
·
Published
2026-07-17
·
Updated
2026-08-31
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A flaw exists in the
keycloak-services component. The token redemption handler for Client-Initiated Backchannel Authentication (CIBA) lacks brute-force protection checks. This allows an attacker possessing valid client credentials to obtain access and refresh tokens for a user account that is currently locked due to brute-force protection, as long as the authentication request was initiated before the lockout and received user approval.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak