External Control of Assumed-Immutable Web Parameter in Keycloak - CVE-2026-7571
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to obtain access tokens and disclose sensitive information.
The vulnerability exists due to external control of assumed-immutable web parameters in the OIDC client data handling during session restart when manipulating client data. A remote user can manipulate client data during a session restart to bypass the control that disables the implicit flow and obtain an access token.
Exploitation requires knowledge of user credentials and a client ID. Access tokens may be exposed in server logs, proxy logs, and HTTP Referrer headers.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-7571
Red Hat build of Keycloak - update to 26.4.12