Insufficient Session Expiration in Keycloak - CVE-2026-9705
Published: June 29, 2026
Keycloak
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and compromise integrity.
The vulnerability exists due to insufficient session expiration in the client registration service when processing requests with a previously issued registration access token. A remote attacker can use a stale registration access token to re-enable a disabled client and reset its secret to disclose sensitive information and compromise integrity.
Exploitation requires possession of a previously issued registration access token for the client.