Missing Authorization in Keycloak - CVE-2026-79652
Published: August 25, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to obtain unauthorized access to a user account at a consent-gated client.
The vulnerability exists due to missing authorization in the JWT Bearer authorization grant implementation within the keycloak-services component when issuing access tokens through the JWT Bearer grant. A remote user can present valid client credentials and a trusted identity provider assertion to bypass the user-consent requirement and obtain unauthorized access to a user account at a consent-gated client.