Loading market data...
← Back to CVE feed

CVE-2026-16089

MEDIUM CVSS 5.4 View on NVD ↗

Description

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
Published: Jul 17, 2026 15:16 UTC Modified: Jul 17, 2026 18:08 UTC