Fedora Account System
Red Hat Associate
Red Hat Customer
A vulnerability was found in Keycloak where the Dynamic Client Registration (DCR) flow does not properly filter sensitive client attributes. Specifically, a registrant using an Initial Access Token can set the internal attribute allow.token.introspection.without.audience.check during the registration process. This attribute disables the mandatory audience verification on the token introspection endpoint. To exploit this flaw, an attacker must possess a valid Initial Access Token for a realm where DCR is enabled. By registering a malicious client with this attribute, the attacker can then use that client's credentials to introspect any active access token they have obtained or intercepted from other clients in the same realm. Successful exploitation results in the disclosure of the full claim set of the token, including user identity, roles, scopes, and session IDs, regardless of whether the introspecting client was the intended audience. This is a bypass of the security controls introduced to fix CVE-2026-37979.