CVE-2026-107121
Received Received - Intake

Keycloak SMTP STARTTLS Downgrade Vulnerability

Vulnerability report for CVE-2026-107121, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
keycloak keycloak_services *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's SMTP email configuration handling. When STARTTLS is enabled, Keycloak does not strictly enforce encrypted connections. An attacker can intercept network traffic and tamper with the encryption request, causing Keycloak to fall back to unencrypted communication. This allows the attacker to capture sensitive email credentials and message content in plain text.

The flaw stems from Keycloak failing to mandate TLS when STARTTLS is configured, permitting silent downgrades to unencrypted traffic. Exploitation requires an active network interception position.

Detection Guidance

To detect this vulnerability, monitor network traffic for SMTP connections using STARTTLS that downgrade to plaintext. Use tools like tcpdump or Wireshark to capture SMTP traffic and check for unencrypted authentication or email content. Commands: tcpdump -i any -w smtp_traffic.pcap port 25 or 587; Wireshark -k -i any -f 'tcp port 25 or 587'.

Impact Analysis

If exploited, this vulnerability allows attackers to intercept and read sensitive email credentials and message content sent by Keycloak. This could lead to unauthorized access to accounts, data breaches, or further attacks using captured credentials.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to the cleartext transmission of sensitive information. GDPR requires protection of personal data, and HIPAA mandates encryption for protected health information. Exploitation may result in data breaches, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Disable STARTTLS in Keycloak's SMTP configuration to prevent fallback to unencrypted connections. Alternatively, restrict network access to SMTP servers or use VPNs to prevent MITM attacks. Monitor for updates from Red Hat for official patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107121. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart