CVE-2026-37979
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
6.5
MEDIUM
CVSS 3.1
EPSS 0.37%
描述
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.
如何修補 CVE-2026-37979
要修補 CVE-2026-37979,請將受影響套件升級到下列已修補版本。
- —升級至 26.6.2 或更新版本
CVE-2026-37979 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 26.6.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |