CVE-2026-37979: Red Hat Build Of Keycloak

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.

Affected products

  • Red Hat Build Of Keycloak: from 26.4, before 26.4.12 (fixed in 26.4.12)

Published 2026-05-19. Last modified 2026-06-17.