CVE-2026-7571 is a vulnerability in Keycloak’s handling of OpenID Connect client data during session restarts. Keycloak does not adequately validate that client configuration parameters, which should be treated as immutable server-side state, have not been tampered with during the restart flow. A low-privilege authenticated user who knows valid user credentials and the target client ID can manipulate client data so that Keycloak treats an OIDC client as if implicit flow were enabled even when administrators have disabled it. As a result, Keycloak may issue an access token in the authorization response where that token should not be available. Because the implicit flow returns tokens in the browser-visible response URL, the flaw can also expose those access tokens through logging and referral mechanisms. The issue is classified as CWE-472.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Keycloak access token disclosure vulnerability mentioned only as part of vendor security history.
A Keycloak vulnerability involving access token disclosure and implicit flow bypass via forged client data, mentioned only as part of vendor security history.
An authentication/security control bypass in Keycloak and potentially Red Hat Single Sign-On that allows a low-privilege authenticated user to tamper with client data during session restart and force issuance of access tokens via the implicit flow, causing token leakage through URLs, logs, proxies, and Referrer headers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.