CVE-2026-16093

Published Jul 17, 2026

Last updated a month ago

Overview

Description
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.
Source
secalert@redhat.com
NVD status
Analyzed
Products
build_of_keycloak, data_grid, jboss_enterprise_application_platform_expansion_pack, single_sign-on

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.4
Impact score
2.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

secalert@redhat.com
CWE-807

Social media

Hype score
Not currently trending

Configurations