Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 06 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client configuration. This allows an attacker who has stolen a user's password to bypass mandatory multi-factor authentication and gain unauthorized access to the Keycloak Admin REST API. | |
| Title | Keycloak-services: keycloak-services: device authorization grant bypasses per-client minimum.acr.value enforcement | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-06T12:44:17.153Z
Reserved: 2026-10-05T05:38:12.281Z
Link: CVE-2026-105305
No data.
Status : Received
Published: 2026-10-06T08:16:35.697
Modified: 2026-10-06T08:16:35.697
Link: CVE-2026-105305
OpenCVE Enrichment
Updated: 2026-10-06T08:30:18Z
-
CWE-287
Improper Authentication