VYPR
advisoryPublished Oct 9, 2026· Updated Oct 10, 2026· 1 source

Keycloak: Three Medium-Severity Flaws in Auth Components Disclosed Together

Key findings • Three medium-severity vulnerabilities in Keycloak disclosed on October 9, 2026. • CVE-2026-107889 allows stored XSS via login theme injection. • CVE-2026-107604 exposes con…

Key findings

  • Three medium-severity vulnerabilities in Keycloak disclosed on October 9, 2026.
  • CVE-2026-107889 allows stored XSS via login theme injection.
  • CVE-2026-107604 exposes confidential client secrets to read-only administrators.
  • CVE-2026-107623 causes silent disabling of OIDC backchannel logout settings.
  • All issues addressed by the Keycloak security team; update recommended.

On October 9, 2026, a batch of three medium-severity vulnerabilities was disclosed for Keycloak, an open-source identity and access management solution. The vulnerabilities, reported by the Keycloak security team, were published within a 14-hour window and highlight issues in theme rendering, client registration, and OpenID Connect (OIDC) dynamic client registration. These flaws could potentially lead to unauthorized script execution and the exposure of sensitive client secrets.

One of the disclosed vulnerabilities, CVE-2026-107889, affects the login theme rendering component. A bypass of the security filter designed to sanitize user input allows a realm administrator to inject malicious scripts into display fields. This stored cross-site scripting (XSS) vulnerability could enable the execution of arbitrary JavaScript in the browsers of other users, potentially leading to session hijacking or other malicious activities.

Another vulnerability, CVE-2026-107604, impacts the installation provider and client registration endpoints. A realm administrator with only read-only permissions for viewing clients can access the primary secret of confidential clients, which should be a protected attribute. This exposure of sensitive credentials could allow unauthorized parties to impersonate legitimate clients and gain access to protected resources.

The third vulnerability, CVE-2026-107623, resides in the OIDC Dynamic Client Registration (DCR) component. A bug in the response serialization process leads to the omission of the backchannel logout offline token revocation setting. This oversight can cause the setting to be silently disabled when a client updates its registration, potentially weakening the security of client logout processes.

All three vulnerabilities were addressed by the Keycloak security team. Users are advised to update to the latest available version to mitigate these risks. The timely disclosure and patching of these issues by the Keycloak team underscore the importance of ongoing security maintenance for identity management systems.

This batch of vulnerabilities serves as a reminder for Keycloak administrators to remain vigilant about security updates and to review their configurations, particularly concerning client secrets and theme customizations. Ensuring that Keycloak is kept up-to-date is crucial for maintaining the integrity and security of authentication and authorization processes.

Synthesized by Vypr AI