CVE-2026-88770
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in Keycloak via Device Grant

Vulnerability report for CVE-2026-88770, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: redhat-SADP

Description

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can complete the device login process and receive new security tokens. This allows the attacker to maintain access to the account even when it should be temporarily disabled to prevent unauthorized entry.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak to 2.11.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's Device Authorization Grant flow. It allows an attacker with an active session for a locked account to bypass brute-force protection and receive new security tokens. The issue occurs because the token redemption process does not check if the user account is locked, even when temporary lockouts are in place.

Detection Guidance

Detecting this vulnerability requires checking Keycloak logs for unusual device authorization grant activity during brute-force lockouts. Look for successful token redemption events where the user account was locked. Review logs for DeviceGrantType class interactions and verify if brute-force protection status was bypassed.

Impact Analysis

An attacker could maintain unauthorized access to your account even after it is locked due to brute-force protection. This requires the attacker to have a valid session before the lockout occurs. The impact includes potential unauthorized data access or actions performed under your identity.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection such as GDPR and HIPAA. It undermines access control mechanisms designed to protect user accounts and data integrity.

Mitigation Strategies

No official mitigation is currently available from Red Hat. As a temporary workaround, disable the Device Authorization Grant flow in Keycloak configuration until a patch is released. Monitor Red Hat's security advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88770. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart