Sceawere
Vulnerability Detail
CVE-2026-107121UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Keycloak SMTP STARTTLS Protocol Downgrade
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- Attack Type
- Cleartext Transmission of Sensitive Information
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-07T08:16:57.053Z",
"pubdate": "2026-10-07T08:16:57.053Z",
"executiveSummary": "A critical security flaw exists in the SMTP email configuration handling within the keycloak-services component, involving an improper implementation of the STARTTLS protocol.\nThe vulnerability manifests as a STARTTLS stripping or protocol downgrade attack, where the application fails to strictly enforce mandatory encryption for outgoing SMTP communications.\nIf the STARTTLS negotiation process is tampered with by a malicious actor positioned in a man-in-the-middle (MITM) capacity, Keycloak may silently fallback to an unencrypted communication channel.\nThis vulnerability allows an attacker to intercept network traffic between the Keycloak server and the SMTP mail server, facilitating the cleartext exposure of sensitive information.\nImpacted data includes SMTP authentication credentials and the full contents of transmitted emails, which may contain sensitive identity management data or password reset tokens.\nThe attack requires the adversary to be capable of intercepting and manipulating network packets in transit, typically requiring positioning within the network path or ARP spoofing/DNS poisoning capabilities.\nThis flaw presents significant risks to confidentiality and data integrity, potentially compromising the credentials used for email integration and exposing sensitive organizational communications to unauthorized third parties.",
"technicalDetails": "The vulnerability resides within the keycloak-services component responsible for managing SMTP server interactions. The root cause is a deficiency in the STARTTLS handshake logic where the client (Keycloak) does not implement a 'strict' or 'mandatory' enforcement policy for encrypted channels.\nUnder normal conditions, Keycloak issues a STARTTLS command to the SMTP server to upgrade an insecure connection to a TLS-encrypted session. However, the implementation does not properly validate the server's response to the upgrade request nor does it terminate the connection if the server signals that it cannot support or establish the requested TLS session.\nAn attacker positioned as a Man-in-the-Middle (MITM) can intercept the initial SMTP handshake. When the Keycloak server issues the STARTTLS command, the attacker intercepts this packet and modifies it or prevents the SMTP server from receiving the command. Simultaneously, the attacker responds to the Keycloak server as if the SMTP server does not support TLS or has rejected the upgrade request.\nBecause the keycloak-services component lacks strict enforcement, it proceeds to transmit subsequent SMTP commands—including the AUTH LOGIN or AUTH PLAIN commands—over the unencrypted connection. The attacker then captures these cleartext SMTP credentials and any following email payloads, which may contain critical authentication links or sensitive system alerts.\nThis behavior represents a failure in security controls where the application prioritizes connectivity over security assurance. The vulnerability is exploitable via network sniffing and traffic manipulation, provided the attacker can intercept traffic between the Keycloak instance and the target Mail Transfer Agent (MTA).\nThe scope of exploitation extends to any communication initiated by the keycloak-services component for administrative notifications, user verification, or password recovery flows. Post-exploitation, the attacker gains static credentials for the email account, which may grant them persistent access to the organization's email infrastructure, potentially facilitating further identity-based attacks or credential harvesting against Keycloak users.\nNo specific user privileges or prior authentication are required to trigger this vulnerability, as the exploit relies solely on network-level manipulation during the SMTP session initiation. The vulnerability affects all configurations where STARTTLS is enabled but not governed by a mandatory encryption requirement within the application's SMTP provider settings."
}