Sceawere

Vulnerability Detail

CVE-2026-105306UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Keycloak Dynamic Registration Security Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
12h ago
Vendor
Red Hat
Product
Red Hat Build of Keycloak
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T06:16:58.530Z",
  "pubdate": "2026-10-05T06:16:58.530Z",
  "executiveSummary": "A critical security flaw exists within the Dynamic Client Registration flow of the Keycloak identity and access management server. The vulnerability stems from improper input validation where the registration process fails to sanitize security-sensitive client attributes during the creation of new client entities.\nBy leveraging a valid Initial Access Token (IAT), an attacker can register a malicious client configured with elevated or unauthorized attributes. This exploit bypasses standard audience validation protocols during token introspection.\nThe primary impact is the unauthorized disclosure of sensitive security tokens. An attacker can successfully view identity information, assigned roles, and session metadata from tokens issued to other applications within the same realm. This constitutes a significant privilege escalation and information disclosure risk, as it allows attackers to monitor cross-application authentication state.\nExploitation requires an attacker to possess a legitimate Initial Access Token, typically acquired through environment misconfiguration or internal access. Once the malicious client is registered, the attacker can manipulate introspection requests to extract cross-tenant intelligence, severely compromising the confidentiality and integrity of the authentication ecosystem.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient server-side sanitization of client attributes during the Dynamic Client Registration process. Keycloak's implementation fails to enforce a restrictive allow-list or filter for specific configuration parameters provided during the registration request. Consequently, an authenticated entity (via an Initial Access Token) can inject or override sensitive client-level attributes that should strictly remain under administrative control.\nThe exploitation flow begins with the attacker utilizing a valid Initial Access Token to perform a POST request to the Dynamic Client Registration endpoint. During this registration request, the attacker specifies a crafted client payload. Because the server does not filter sensitive attributes, the attacker can force the new client to adopt configurations that alter its behavior during OIDC introspection.\nSpecifically, the attacker leverages the improperly registered client to manipulate the audience (aud) and scope validation checks performed by the introspection endpoint. When the attacker presents a token associated with another application to the introspection endpoint using the compromised client, the server fails to correctly enforce audience constraints. This bypass allows the introspection service to return full identity claims, roles, and session identifiers that would otherwise be redacted or blocked due to audience mismatch.\nThe vulnerable component is the Dynamic Client Registration service within the Keycloak core, specifically the request parsing and validation logic that processes incoming client registration JSON objects. The absence of a robust attribute-filtering mechanism allows for the persistent storage of malicious configurations within the underlying database. The vulnerability does not require complex remote code execution; rather, it represents a logic flaw in the OAuth 2.0/OIDC implementation where client-defined metadata overrides security enforcement boundaries.\nSuccessful exploitation results in total compromise of the visibility of session tokens across the realm. Post-exploitation, an attacker can maintain an automated reconnaissance capability, intercepting the claims of other users or service accounts by simply passing target tokens through the introspection endpoint of the malicious client. This allows the attacker to reconstruct session contexts, identify administrative accounts, and exfiltrate sensitive claims that inform further attacks, such as lateral movement or privilege escalation within the identity provider architecture."
}
CVE-2026-105306: Keycloak Dynamic Registration Security Bypass (MEDIUM Severity, CVSS: 6.5) | Sceawere