CVE-2026-46389
Description
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the client-kubernetes-secret Keycloak client authenticator (shipped by uds-identity-config and consumed by UDS Core) causes the submitted client_secret to be overwritten with the mounted Kubernetes secret before comparison. An attacker who can reach the Keycloak token endpoint and knows a client_id using this authenticator can authenticate as that client with any client_secret value and obtain OAuth2 tokens scoped to the client's service account. In the case of the uds-operator client this token can be used to registry/modify other clients. Version 0.26.1 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:defenseunicorns:uds_identity_config:*:*:*:*:*:*:*:*range: >=0.11.0,<0.26.1
Patches
Vulnerability mechanics
References
2- github.com/defenseunicorns/uds-identity-config/security/advisories/GHSA-8mg2-6588-r4hwnvdMitigationVendor Advisory
- github.com/defenseunicorns/uds-identity-config/releases/tag/v0.26.1nvdProductRelease Notes
News mentions
0No linked articles in our index yet.