🔐 CVE Alert

CVE-2026-1035

LOW 3.1

Org.keycloak.protocol.oidc: keycloak refresh token reuse bypass via toctou race condition

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
1th

A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.

CWE CWE-367
Vendor red hat
Product red hat build of keycloak 26.4
Published Jan 21, 2026
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak 26.4

Be the first to know when new low vulnerabilities affecting red hat red hat build of keycloak 26.4 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4.11
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform 8
All versions affected
Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Pack
All versions affected
Red Hat / Red Hat Single Sign-On 7
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6477 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6478 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-1035 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2430314

Credits

Red Hat would like to thank Mohamed Amine ait Ouchebou (mrecho) (Indiesecurity) for reporting this issue.