PT-2026-3754 · Red Hat · Keycloak

Mohamed Amine Ait Ouchebou

+1

·

Published

2026-01-21

·

Updated

2026-01-21

·

CVE-2026-1035

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in Keycloak’s refresh token processing within the TokenManager class, specifically related to enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This non-atomic operation allows concurrent refresh requests to bypass single-use enforcement, potentially resulting in the issuance of multiple access tokens from a single refresh token. This undermines Keycloak’s refresh token rotation hardening. The issue involves a race condition in the TokenManager that enables unauthorized access token generation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2026-1035
GHSA-M2W5-7XHV-W6FH

Affected Products

Keycloak