A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-15943 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2501270 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-17 12:17
Updated : 2026-08-09 14:56
NVD link : CVE-2026-15943
Mitre link : CVE-2026-15943
CVE.ORG link : CVE-2026-15943
JSON object : View
Products Affected
redhat
- build_of_keycloak
CWE
CWE-1288
Improper Validation of Consistency within Input
