Incorrect authorization in Keycloak - CVE-2025-14559
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to obtain access and refresh tokens for disabled users and use previously revoked privileges.
The vulnerability exists due to incorrect authorization in the Token Exchange implementation of the keycloak-services component when a privileged client invokes the token exchange flow. A remote privileged user can invoke the token exchange flow for a disabled user to obtain access and refresh tokens for that user and use previously revoked privileges.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-14559
Red Hat build of Keycloak - update to 26.4.9