CVE-2026-16089: A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that o
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-16089
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-160890.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16089 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for keycloak-services component of
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- lowCVE-2026-18209: A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect …nvd · 2026-07-31
- mediumCVE-2026-18208: A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. …nvd · 2026-07-31
- lowCVE-2026-18206: A flaw was found in the keycloak-services component of Keycloak, which provides identity and a…nvd · 2026-07-31
- mediumCVE-2026-17059: A flaw was found in the role-users endpoint of the keycloak-services library, which is the cor…nvd · 2026-07-24
- mediumCVE-2026-16104: A flaw was found in the authentication configuration endpoint of the keycloak-services compone…nvd · 2026-07-17
- mediumCVE-2026-16103: A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete f…nvd · 2026-07-17
More from NVD Recent CVEs
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01