Bug 2545802 (CVE-2026-105306) - CVE-2026-105306 keycloak-services: keycloak-services: Token introspection audience bypass via Dynamic Client Registration
Summary: CVE-2026-105306 keycloak-services: keycloak-services: Token introspection aud...
Keywords:
Status: NEW
Alias: CVE-2026-105306
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-05 05:41 UTC by OSIDB Bzimport
Modified: 2026-10-05 05:41 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-05 05:41:12 UTC
A vulnerability was found in Keycloak where the Dynamic Client Registration (DCR) flow does not properly filter sensitive client attributes. Specifically, a registrant using an Initial Access Token can set the internal attribute allow.token.introspection.without.audience.check during the registration process. This attribute disables the mandatory audience verification on the token introspection endpoint.
To exploit this flaw, an attacker must possess a valid Initial Access Token for a realm where DCR is enabled. By registering a malicious client with this attribute, the attacker can then use that client's credentials to introspect any active access token they have obtained or intercepted from other clients in the same realm. Successful exploitation results in the disclosure of the full claim set of the token, including user identity, roles, scopes, and session IDs, regardless of whether the introspecting client was the intended audience. This is a bypass of the security controls introduced to fix CVE-2026-37979.


Note You need to log in before you can comment on or make changes to this bug.