PT-2026-3753 · Red Hat · Keycloak

Published

2026-01-21

·

Updated

2026-02-10

·

CVE-2025-14559

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the keycloak-services component of Keycloak. This issue allows the issuance of access and refresh tokens for disabled users, potentially leading to unauthorized use of previously revoked privileges. The root cause is a business logic vulnerability within the Token Exchange implementation when a privileged client initiates the token exchange flow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-01119
CVE-2025-14559
GHSA-WV3H-X6C4-R867

Affected Products

Keycloak