Skip to content
Critical Vulnerability in Keycloak CVE-2026-97846 Exposes Token Security

Critical Vulnerability in Keycloak CVE-2026-97846 Exposes Token Security

First seen 26 Sep 2026, 04:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 26, 2026 at 05:24 UTC
  • •CVE-2026-97846 allows token bypass in Keycloak's Standard Token Exchange V2 feature.
  • •Exploitation requires valid client credentials and specific configurations.
  • •No effective mitigation is currently available; users should monitor for updates.

A vulnerability identified as CVE-2026-97846 in Keycloak's Standard Token Exchange V2 feature allows attackers with stolen client credentials to bypass mTLS holder-of-key binding protections. This flaw enables the acquisition of unrestricted Bearer tokens, potentially leading to unauthorized access to sensitive resources. The vulnerability is rated as moderate due to the requirement for valid client credentials and specific configurations for exploitation. Currently, no effective mitigation or fix is available, and organizations are advised to monitor Red Hat advisories for updates. The vulnerability impacts confidentiality and integrity but does not affect system availability. Exploitation complexity is high, requiring significant effort and specific conditions. Keycloak users are urged to limit credential exposure and review configurations to reduce risk until a patch is released.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-25
CVE-2026-97846 published
Red Hat disclosed a vulnerability in Keycloak affecting token security due to improper authentication.
cve.akaoma.com
2026-09-26
Vulnerability reported by multiple sources
Various cybersecurity outlets reported on CVE-2026-97846, detailing its implications and risks.
radar.offseq.com
2026-09-26
Mitigation recommendations issued
Red Hat advised users to limit credential exposure and review configurations until a fix is available.
access.redhat.com
2026-09-26
CVE-2026-100599 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-26
CVE-2026-100596 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-26
CVE-2026-100598 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-26
CVE-2026-100597 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (5)

Following this threat?

Track Feedly and CVE-2026-100596 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed