Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the org.keycloak.protocol.oidc package of Keycloak. The OAuth 2.0 Device Authorization Grant flow does not correctly enforce the per-client minimum.acr.value setting. While the standard Authorization Code flow properly requires multi-factor authentication (MFA) when this setting is present, the Device Authorization flow allows authentication to complete at a lower Level of Assurance (LoA 1, password only). The root cause is a missing validation step in the device grant code path to ensure the resulting authentication context class reference (ACR) meets the client's configured minimum. An attacker with knowledge of a user's primary credentials can exploit this to bypass MFA requirements. Successful exploitation allows the attacker to obtain a valid access token with the client's scoped roles and use it to perform unauthorized actions via the Keycloak Admin REST API, such as managing users or modifying realm configurations.