Red HatCVE-2026-16089
Red Hat keycloak-services: session fixation
Medium5.4CVE-2026-16089 · Published Jul 17, 2026 · updated Sep 16, 2026
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | Red Hat xdgmime: heap buffer overflow | High7.1 | No fix yet |
| Jul 17 | Red Hat Data Grid 8: untrusted input in a security decision | Medium5.4 | No fix yet |
| Jul 17 | Red Hat keycloak-services: attacker could obtain access | Medium4.3 | No fix yet |
| Jul 17 | Red Hat Data Grid 8: weakly protected credentials | Medium4.3 | No fix yet |
| Jul 17 | Red Hat admin REST API of Keycloak: missing authorization | Medium4.9 | No fix yet |
| Jul 17 | Red Hat default-groups REST endpoint: information disclosure | Medium4.3 | No fix yet |