Bug 2540949 (CVE-2026-97846) - CVE-2026-97846 keycloak-services: keycloak-services: Standard Token Exchange V2 bypasses mTLS holder-of-key binding
Summary: CVE-2026-97846 keycloak-services: keycloak-services: Standard Token Exchange ...
Keywords:
Status: NEW
Alias: CVE-2026-97846
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 05:55 UTC by OSIDB Bzimport
Modified: 2026-09-25 05:55 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 05:55:48 UTC
A vulnerability was found in Keycloak where the Standard Token Exchange V2 grant path fails to enforce mTLS holder-of-key token binding. When a confidential client is configured with tls.client.certificate.bound.access.tokens set to true, Keycloak correctly rejects standard token grants if no client certificate is provided. However, an attacker who possesses the client credentials and a valid subject token can use the Standard Token Exchange V2 endpoint to obtain an active Bearer access token without presenting a TLS client certificate. The resulting token lacks the cnf.x5t#S256 claim, effectively bypassing the configured sender-constraint and allowing unauthorized access to protected resources.


Note You need to log in before you can comment on or make changes to this bug.