CVE-2026-7571
Redhat Build Of Keycloak 26.4 – 26.4.12
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NSummary
CVE-2026-7571 is a high-severity External Control of Assumed-Immutable Web Parameter (CWE-472) vulnerability in Redhat Build Of Keycloak. Its CVSS base score is 7.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 27th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-30888
Vulnerability Data
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session…
more
restart, an attacker can obtain an access token that should not be available. This vulnerability can also lead to the exposure of these access tokens in server logs, proxy logs, and HTTP Referrer headers, resulting in sensitive information disclosure.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
SI-10 directly requires validation of all inputs, eliminating the assumption that client-supplied parameters remain immutable.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require server-side validation of all inputs instead of trusting client-supplied immutable parameters.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure coding standards require server-side verification of client-supplied data, eliminating the root cause of external control of immutable parameters.
Security testing in development and acceptance will detect parameter tampering vulnerabilities before deployment.
Secure development lifecycle mandates input validation and integrity checks that directly prevent external tampering of assumed-immutable parameters.
Application security requirements explicitly call for validation of all inputs, including hidden fields, mitigating CWE-472.
Information access restriction can limit which parameters users may influence, providing a secondary layer of defense.