Incorrect authorization in Keycloak - CVE-2025-14559

 

Incorrect authorization in Keycloak - CVE-2025-14559

Published: September 10, 2026


Vulnerability identifier: #VU148914
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14559
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to obtain access and refresh tokens for disabled users and use previously revoked privileges.

The vulnerability exists due to incorrect authorization in the Token Exchange implementation of the keycloak-services component when a privileged client invokes the token exchange flow. A remote privileged user can invoke the token exchange flow for a disabled user to obtain access and refresh tokens for that user and use previously revoked privileges.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2025-14559

Install security update from vendor's website.

Keycloak - addressed in versions 26.4.9, 26.5.2
Red Hat build of Keycloak - update to 26.4.9

External References

Related Security Bulletins