Listen to this Post
How the mentioned CVE works:
In Keycloak, when a client is configured with the `offline_access` scope, it can request refresh tokens to obtain long-lived offline sessions. The vulnerability occurs when an administrator removes the `offline_access` scope from a client’s configuration. While this action should immediately invalidate all existing offline sessions and refresh tokens for that client, it does not. The system fails to perform this necessary invalidation. Consequently, any previously issued refresh tokens remain functional. An attacker in possession of such a token can continue to use it to generate new access tokens, effectively maintaining access to the user’s session indefinitely. This creates a mismatch between the administrator’s expectation and the system’s actual state, leading to prolonged, unauthorized access even after the permission for offline sessions has been revoked.
Platform: Keycloak
Version: (Multiple versions)
Vulnerability: Improper Session Invalidation
Severity: Moderate
date: 2025-10-23
Prediction: Expected Patch Date: 2025-11-13
What Undercode Say:
curl -X GET "http://keycloak-host:8080/realms/master/protocol/openid-connect/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=refresh_token&client_id=admin-cli&refresh_token=<OFFLINE_REFRESH_TOKEN>"
// Code snippet checking for offline session validity
if (token.isOfflineSession()) {
// Vulnerability: Missing check for revoked offline_access scope on the client
if (!client.hasOfflineAccessScope()) {
// This invalidation logic was missing
throw new SessionExpiredException();
}
}
How Exploit:
Attacker uses a previously acquired, valid offline refresh token to request new access tokens, even after the `offline_access` scope has been removed from the client by an administrator.
Protection from this CVE:
Apply vendor patch when available. Manually revoke existing offline sessions after removing the `offline_access` scope from a client. Monitor for unusual token refresh activity.
Impact:
Prolonged unauthorized access despite administrative action to restrict permissions, leading to potential data exposure and privilege retention.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

