Bug 2545800 (CVE-2026-105302) - CVE-2026-105302 keycloak-services: keycloak-services: User Session Note mapper exposes upstream IdP access tokens
Summary: CVE-2026-105302 keycloak-services: keycloak-services: User Session Note mappe...
Keywords:
Status: NEW
Alias: CVE-2026-105302
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-05 05:33 UTC by OSIDB Bzimport
Modified: 2026-10-05 05:33 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-05 05:33:15 UTC
A vulnerability was found in Keycloak where the User Session Note mapper (oidc-usersessionmodel-note-mapper) fails to restrict access to sensitive internal session notes. When a user authenticates through an external identity provider (IdP), Keycloak stores the upstream access and refresh tokens as internal user session notes (FEDERATED_ACCESS_TOKEN and FEDERATED_REFRESH_TOKEN).
A delegated administrator with manage permissions for an OIDC client can configure a mapper to copy these internal notes into the client's issued tokens. Because the mapper accepts any note name without validation, it allows a client manager to bypass the dedicated broker-token retrieval API and its associated security checks (such as the broker.read-token role).
Successful exploitation requires the attacker to have Fine-Grained Admin Permission (FGAP) to manage at least one OIDC client and for the deployment to have session token storage enabled (default in Identity Brokering API v1). An attacker can then observe the tokens issued to their managed application to obtain a victim's upstream bearer tokens, which are directly usable against the external identity provider to access the victim's account information or perform actions on their behalf.


Note You need to log in before you can comment on or make changes to this bug.