CVE-2026-16089
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
- EPSS probability
- 0.14%
- CWE
- CWE-472
- Published
- 2026-07-17
- Last modified
- 2026-08-31
Weakness type
Related vulnerabilities
- CVE-2026-84762 — WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability
- CVE-2026-77999 — Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
- CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-1982 — Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget
- CVE-2026-7484 — Improper Access Control in Abis Technology's AVESİS
- CVE-2026-65052 — Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields
- CVE-2026-56877 — The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not...
- CVE-2026-59817 — Ghost: Paid gift memberships obtainable at minimal cost via the donations feature