keycloak-services is vulnerable to Improper Access Control
81
High Risk
When the JWT authorization grant preview feature is enabled, keycloak-services issues tokens through the grant without checking whether the resolved user account is enabled. A user whose account has been disabled continues to obtain access and refresh tokens through the JWT authorization grant. The grant processing associates the resolved user with the token-issuing event and proceeds straight to issuance with no enabled-status or required-actions gate. The fix rejects disabled users and accounts with pending required actions before any token is issued.
You are affected if you are using a version that falls within the vulnerable range and you have enabled the JWT authorization grant preview feature.
keycloak-services is vulnerable to Improper Access Control in versions 26.5.0 - 26.5.2.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.