PatchSiren cyber security CVE debrief
CVE-2026-15943 Red Hat CVE debrief
A flaw was found in the Keycloak keycloak-services component, which handles identity provider management. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret. This highlights the importance of proper validation and secret management in identity provider configurations.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-17
- Original CVE updated
- 2026-08-09
- Advisory published
- 2026-07-17
- Advisory updated
- 2026-08-09
Who should care
Users of Keycloak keycloak-services component should verify their configurations, update to a fixed version if available, and monitor for suspicious activity. This includes administrators responsible for identity provider management, security teams, and operators of Keycloak deployments. They should review the CVE record and vendor guidance for affected scope and severity.
Technical summary
The Keycloak keycloak-services component handles identity provider management. A delegated administrator can update an OIDC identity provider using a masked client secret sentinel value. However, due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed. This allows an attacker to redirect and capture the secret, emphasizing the need for proper validation and secret management in Keycloak configurations.
Defensive priority
Medium priority due to CVSS score of 5.5 and potential for secret capture.
Recommended defensive actions
- Verify Keycloak keycloak-services component configurations
- Update to a fixed version if available
- Monitor for suspicious activity
- Implement compensating controls for secret management
- Review vendor guidance for affected scope and severity
- Conduct exposure review for Keycloak deployments
- Track exceptions and retest remediated assets
Evidence notes
Evidence is limited. Primary official records indicate a flaw in Keycloak keycloak-services component. Vendor remediation and compensating controls are recommended. The issue involves improper validation of security-sensitive fields when updating an OIDC identity provider, allowing potential secret capture. Defenders should verify configurations, monitor for suspicious activity, and implement additional security measures.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15943 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15943
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15943 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15943
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-15943
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.