A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful exploitation grants the attacker unauthorized access to the victim's account, potentially leading to information disclosure or privilege escalation.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* |
Thu, 28 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 28 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
|
|
| Vendors & Products |
Redhat build Of Keycloak
|
Thu, 28 May 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful exploitation grants the attacker unauthorized access to the victim's account, potentially leading to information disclosure or privilege escalation. | |
| Title | Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-05-28T04:47:10.497Z
Updated: 2026-05-28T13:00:32.592Z
Reserved: 2026-05-28T04:02:07.242Z
Link: CVE-2026-9802
Updated: 2026-05-28T13:00:25.484Z
Status : Analyzed
Published: 2026-05-28T06:16:29.620
Modified: 2026-06-03T19:36:47.130
Link: CVE-2026-9802