Keycloak
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*
- 26.5.2
A vulnerability exists in Keycloak's JWT authorization grant preview feature, specifically in version 26.5.2. When this feature is enabled, Keycloak does not properly validate the disabled status of user accounts during JWT authorization processing. This flaw allows remote attackers with low privileges to exploit the system by using a valid assertion token from an external identity provider to obtain a JWT for a disabled user, thereby gaining unauthorized access to sensitive resources.
Exploitation of this vulnerability could lead to unauthorized access to sensitive resources by allowing disabled users to obtain JWTs that bypass access controls.
To address this vulnerability, disable the 'jwt-authorization-grant' preview feature in Keycloak deployments. This feature is usually disabled by default, but if it has been turned on, it should be disabled to prevent unauthorized access through disabled user accounts. After disabling the feature, a restart of the Keycloak service may be necessary for the changes to take effect.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.