Sceawere

Vulnerability Detail

CVE-2026-105302UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Keycloak Session Note Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.7
Creation Date
12h ago
Vendor
Red Hat
Product
Red Hat Build of Keycloak
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a delegated client administrator to leak a user's upstream bearer tokens into the tokens issued to their managed application, potentially leading to unauthorized access to the user's data on external platforms.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.7",
  "pubDate": "2026-10-05T06:16:58.383Z",
  "pubdate": "2026-10-05T06:16:58.383Z",
  "executiveSummary": "A critical information disclosure vulnerability exists within the User Session Note mapper component of the Keycloak identity and access management platform.\nThe vulnerability allows an authenticated client administrator with delegated permissions to improperly access sensitive data stored within user sessions.\nBy manipulating the session note mapping configuration, an attacker can extract internal credentials, specifically federated access tokens issued by external identity providers.\nThis flaw facilitates the unauthorized exfiltration of upstream bearer tokens, which may be leveraged by the attacker to impersonate the user and access protected resources on third-party platforms.\nThe risk is significant as it breaks the principle of least privilege, allowing administrative users to transcend their intended scope and compromise external user sessions.\nSuccessful exploitation requires the attacker to hold delegated administrative privileges over a specific client, enabling them to configure or interact with the User Session Note mapper functionality.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient input validation and lack of restrictive allow-listing within the User Session Note mapper implementation in Keycloak.\nThe mapper is designed to include specific user session attributes in the tokens issued to client applications; however, it fails to filter or sanitize requests for internal session notes.\nKeycloak maintains internal session state, which often includes sensitive metadata such as federated identity tokens (OAuth2/OIDC access tokens, refresh tokens) obtained during the initial authentication flow with external identity providers.\nAn attacker possessing the 'realm-management' client administrator role or specific delegated administration rights over a client application can modify the mapper settings to request these restricted session notes.\nThe exploitation flow proceeds as follows: First, the attacker identifies the internal key identifier for a desired federated access token stored within the user session. Second, the attacker configures a User Session Note mapper for their managed client to map this specific internal key to a custom claim within the issued JWT (JSON Web Token). Third, upon a subsequent token request by a victim user (or the attacker acting as a user), Keycloak executes the mapper logic.\nBecause the mapper does not perform an authorization check against the requested note's sensitivity level, it retrieves the sensitive federated token from the session object and embeds it directly into the issued client token.\nThe attacker then retrieves the token issued to the client application, inspects the custom claim, and extracts the upstream bearer token.\nThis allows the attacker to utilize the exfiltrated bearer token to authenticate against external APIs and services on behalf of the user, effectively bypassing the intended security boundaries of the Keycloak session management framework.\nThe vulnerability highlights a failure in the trust boundary between the identity provider's internal state management and the client-facing token generation process."
}
CVE-2026-105302: Keycloak Session Note Information Disclosure (MEDIUM Severity, CVSS: 5.7) | Sceawere