CVE-2026-16103
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS probability
- 0.34%
- CWE
- CWE-305
- Published
- 2026-07-17
- Last modified
- 2026-08-31
Weakness type
Related vulnerabilities
- CVE-2026-86207 — Authentication bypass leads to unauthorised access to N-central
- CVE-2026-81578 — PaperCut MF/NG: Authentication Bypass
- CVE-2026-16895 — Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2026-53561 — Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user
- CVE-2025-14600 — Admin Account Takeover via Path Traversal in vsDesk
- CVE-2026-19349 — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
- CVE-2026-1621 — Register Bypass in Universal Sotware's E-Municipality