CVE-2026-16089
Estado: ModificadaMedia (5.9)—
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-472
- CWE-384
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-16089",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-16089",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-22T18:19:51.675300Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 1.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.6::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.6",
"versions": [
{
"status": "unaffected",
"version": "26.6.7-3",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhbk/keycloak-operator-bundle",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.6::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.6",
"versions": [
{
"status": "unaffected",
"version": "26.6-20",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhbk/keycloak-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.6::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.6",
"versions": [
{
"status": "unaffected",
"version": "26.6-20",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhbk/keycloak-rhel9-operator",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.6::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.6.7",
"packageName": "keycloak-services",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.6::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.6.7",
"packageName": "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:build_keycloak:26.6::el9"
],
"vendor": "Red Hat",
"product": "Red Hat build of Keycloak 26.6.7",
"packageName": "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:jboss_data_grid:8"
],
"vendor": "Red Hat",
"product": "Red Hat Data Grid 8",
"packageName": "keycloak-services",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:jbosseapxp"
],
"vendor": "Red Hat",
"product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
"packageName": "keycloak-services",
"collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:red_hat_single_sign_on:7"
],
"vendor": "Red Hat",
"product": "Red Hat Single Sign-On 7",
"packageName": "keycloak-services",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-07-17T15:16:46.317",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2026:68277",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:68278",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-16089",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501724",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-472"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-384"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity."
}
],
"lastModified": "2026-09-16T19:17:07.217",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}