Sceawere
Vulnerability Detail
CVE-2026-107889UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Keycloak Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 5h ago
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in the login theme rendering component of Keycloak. The issue occurs because the security filter responsible for cleaning user input can be bypassed, allowing a realm administrator to store malicious scripts in display fields. This could result in unauthorized JavaScript execution in the browsers of users visiting the login page, potentially leading to data exposure or session interference.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-09T05:16:44.583Z",
"pubdate": "2026-10-09T05:16:44.583Z",
"executiveSummary": "A Stored Cross-Site Scripting (XSS) vulnerability exists within the login theme rendering component of Keycloak.\nThe flaw stems from an insufficient security filter that fails to properly sanitize user-supplied input within display fields.\nThis vulnerability allows an authenticated attacker with realm administrator privileges to inject and persist malicious JavaScript payloads directly into the system's login interface.\nWhen end-users navigate to the compromised login page, the stored script executes within the context of their browser session.\nThe impact includes potential unauthorized access to session tokens, sensitive user data exfiltration, and the facilitation of phishing or further client-side attacks.\nSuccessful exploitation requires the attacker to possess elevated administrative privileges within a specific realm to modify login themes or fields.\nThe risk is significant as it compromises the integrity of the authentication flow and poses a direct threat to the confidentiality and security of all users interacting with the affected login portal.",
"technicalDetails": "The vulnerability resides in the login theme rendering component of Keycloak, specifically within the logic responsible for processing and outputting data from customizable display fields.\nThe root cause is an improper input sanitization mechanism in the security filter layer, which allows bypass techniques that permit the injection of executable HTML and JavaScript tags into persistent storage.\nThe exploitation process begins when a realm administrator leverages their authorized access to the Keycloak administrative console to modify theme-related display fields. By injecting crafted XSS payloads—such as <script>alert(document.cookie)</script> or more sophisticated exfiltration hooks—into these fields, the administrator persists the code within the application's configuration database.\nBecause the rendering component fails to validate or encode the stored content before rendering it to the client-side login page, the browser treats the malicious payload as trusted code rather than literal data. When a victim loads the login page, the injected JavaScript executes within the security context of the Keycloak domain.\nThis execution environment grants the attacker access to sensitive objects, including document cookies (if not protected by HttpOnly flags), local storage, and the ability to modify the Document Object Model (DOM) to capture credentials or manipulate the authentication process in real-time.\nThe attack is highly effective because it remains transparent to the end-user, appearing as legitimate content rendered by the Keycloak server. The exploitation does not require interaction with the server-side logic beyond the initial payload placement, as the malicious code is served automatically to every user who visits the login theme.\nThis vulnerability represents a breakdown in the secure output encoding strategy of the rendering engine, where trust is erroneously placed in user-controlled administrative input. The lack of strict Content Security Policy (CSP) enforcement on the affected pages further exacerbates the potential for successful exploitation, as there are insufficient client-side controls to block the execution of unauthorized scripts."
}