Fedora Account System
Red Hat Associate
Red Hat Customer
original reporting: https://docs.google.com/document/d/1Rf4NtLudECimDNy8F9clUblm6Avx8_yF/edit Auth Bypass — Elytron OAuth2 introspection bearer param-injection enables cross-audience token swap (JBoss EAP) Authentication bypass on any EAP application whose security domain is backed by an Elytron token-realm with <oauth2-introspection>. findings/jboss-eap_111.md
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 Via RHSA-2026:70228 https://access.redhat.com/errata/RHSA-2026:70228
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 Via RHSA-2026:70230 https://access.redhat.com/errata/RHSA-2026:70230
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 Via RHSA-2026:70229 https://access.redhat.com/errata/RHSA-2026:70229
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:70277 https://access.redhat.com/errata/RHSA-2026:70277