MEDIUMVulnerability
CVE-2026-89298
A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service returns the client's confidential secret in cleartext. This could allow a read-only administrator to obtain full access to the affected client's account and potentially escalate their privileges within the realm.
Properties
- severity
- MEDIUM
- score
- 4.9
- cve_id
- CVE-2026-89298
- signal_observed_at
- 2026-09-21T23:07:07+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- published_at
- 2026-09-11T14:17:37.173
- last_modified
- 2026-09-16T19:42:43.623
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph