云虫漏洞库

CVE-2026-79652 - A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client requires user consent before issuing a token. This allows an authenticated attacker with valid client credentials and a trusted identity provider assertion to bypass the - 漏洞详情

漏洞编号:CVE-2026-79652

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-79652

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-862

发布/更新时间:2026-08-25 / 2026-08-28

漏洞描述

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client requires user consent before issuing a token. This allows an authenticated attacker with valid client credentials and a trusted identity provider assertion to bypass the consent requirement and obtain unauthorized access to a user account at a consent-gated client.

相关链接

相关漏洞

« 返回首页