CVE-2026-37979 Details
Description
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.
An access control vulnerability has been identified in Keycloak's OpenID Connect (OIDC) token introspection endpoint. This flaw allows a confidential client to bypass audience restrictions, enabling the retrieval of sensitive token claims intended for other resource servers. The vulnerability arises because the introspection endpoint does not properly validate that the client making the request is included in the token's audience claim before disclosing information. As a result, an attacker-controlled client with valid credentials can intercept or obtain access tokens meant for different audiences and access the full set of claims, including sensitive information that should have been excluded from lightweight access tokens. This issue can be exploited remotely by any confidential client within the same realm that has valid credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:19596 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:19597 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-37979 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2455328 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.12 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |