MEDIUMVulnerability

CVE-2026-79652

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client requires user consent before issuing a token. This allows an authenticated attacker with valid client credentials and a trusted identity provider assertion to bypass the consent requirement and obtain unauthorized access to a user account at a consent-gated client.

Properties

severity
MEDIUM
score
5.9
cve_id
CVE-2026-79652
signal_observed_at
2026-09-16T17:34:19+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
published_at
2026-08-25T11:16:54.850
last_modified
2026-09-16T16:17:16.680

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-79652 — Ninja Signal Threat Intelligence | Ninja Signal