Record summary

CVE-2026-16103 has a selected CVSS score of 4.3 (medium).

Description

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2026 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakkeycloak-services

Default status: affected

CVE ListVersion data not supplied

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat Data Grid 8

Browse Red Hat / Red Hat Data Grid 8keycloak-services

Default status: unaffected

CVE ListVersion data not supplied

Red Hat JBoss Enterprise Application Platform Expansion Pack

Browse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-services

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Single Sign-On 7

Browse Red Hat / Red Hat Single Sign-On 7keycloak-services

Default status: unaffected

CVE ListVersion data not supplied

References

3