Improper access control in Keycloak - CVE-2026-37979
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive token claims.
The vulnerability exists due to improper access control in Keycloak\'s OpenID Connect token introspection endpoint when processing introspection requests from confidential clients. A remote user can use valid confidential-client credentials to bypass audience restrictions and disclose sensitive token claims.
Lightweight access tokens are affected.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-37979
Red Hat build of Keycloak - update to 26.4.12