CVE-2026-107623
Received Received - Intake

OIDC Dynamic Client Registration Backchannel Logout Token Revocation Flaw in Keycloak

Vulnerability report for CVE-2026-107623, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: redhat-SADP

Description

A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's OIDC Dynamic Client Registration (DCR) component. A bug in response serialization omits the backchannel logout offline token revocation setting. When clients update, this silently disables the setting, allowing offline tokens to remain valid even after user session termination.

Detection Guidance

To detect this vulnerability, inspect Keycloak server logs for failed or unusual backchannel logout events. Check if the backchannel_logout_revoke_offline_tokens setting is missing in OIDC DCR responses. Review client configurations for unauthorized modifications to this setting.

Impact Analysis

If you use Keycloak with OIDC DCR, attackers could exploit this to keep offline tokens active after logout. This may allow unauthorized access to resources even when sessions are terminated, potentially leading to data breaches or prolonged account access.

Compliance Impact

This vulnerability could violate GDPR's data retention and access control requirements by allowing unauthorized access to user data via lingering offline tokens. For HIPAA, it may compromise session termination controls, risking unauthorized access to protected health information.

Mitigation Strategies

Update Keycloak to the latest version to address the OIDC Dynamic Client Registration flaw. Verify that the backchannel logout offline token revocation setting is properly enabled after updates. Monitor user sessions and offline tokens for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107623. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart