SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16103

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the keycloak-services component of Keycloak, where brute-force protection is improperly implemented in the token redemption handler, allowing attackers with valid client credentials to bypass account lockouts. This flaw enables unauthorized access to access and refresh tokens for user accounts that have been locked due to brute-force attempts, provided the initial authentication request was initiated prior to the lockout. Organizations using Keycloak for authentication should prioritize addressing this issue to mitigate potential unauthorized access risks.

CVE
CVE-2026-16103
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.

Related CVEs

Other vulnerabilities affecting the same vendor(s)