Time-of-check Time-of-use (TOCTOU) Race Condition in Keycloak - CVE-2026-1035
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to bypass single-use refresh token enforcement.
The vulnerability exists due to a time-of-check time-of-use race condition in the TokenManager class during refresh token processing when strict refresh token rotation is enabled. A remote user can send concurrent refresh requests using the same refresh token to bypass single-use refresh token enforcement.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-1035
Red Hat build of Keycloak - update to 26.4.11