# CVE-2026-16103

## Summary

- **CVE ID:** CVE-2026-16103
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
- **CWE:** CWE-305
- **Published:** Jul 17, 2026
- **Last Modified:** Aug 31, 2026

## Description

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.

## Affected Products

No affected products listed.

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-16103)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2501736)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 27.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._