#VU118565 Insufficient session expiration in Keycloak - CVE-2025-12110
Published: November 17, 2025
Keycloak
Keycloak
Description
The vulnerability allows a remote attacker to compromise session of other users.
The vulnerability exists due to Keycloak does not invalidate offline sessions when the offline_access scope is removed. The refresh token is accepted and you can continue to request new tokens for the session. A remote authenticated attacker can compromise sessions of other user accounts.