Session Fixation in Keycloak - CVE-2026-16089
Published: July 17, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to obtain access tokens for a victim\'s identity.
The vulnerability exists due to improper binding of OAuth 2.0 authorization codes to clients in the keycloak-services component when redeeming an intercepted authorization code. A remote user can modify the intercepted code to redeem it using their own client to obtain access tokens for a victim\'s identity.
User interaction is required.