A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
| Vendor | Product | Versions |
|---|---|---|
| red hat | keycloak | maven/org.keycloak:keycloak-services: < 26.5.7 |
Updated severity to HIGH, marked as actively exploited, and noted no exploit available.
Initial creation