Keycloak Authentication Bypass Vulnerability Due to Missing LDAP Validation After Password Reset

Vulnerability

An authentication bypass vulnerability has been identified in Keycloak. When an Active Directory (AD) user resets their password, Keycloak updates the password without validating the new credentials through an LDAP bind. This oversight allows users with expired or disabled AD accounts to regain access in Keycloak, circumventing AD restrictions. The vulnerability could lead to unauthorized access under certain conditions.

Impact

Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access in Keycloak.

Remediation

Users can upgrade to the Red Hat build of Keycloak 26.0.10, which addresses this vulnerability. Instructions for applying the update are available on the Red Hat Customer Portal.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.