
Severity Daily@severitydaily
Disabling a Keycloak client does not stop its tokens. Refresh keeps minting access tokens that name the disabled client, Red Hat (@RedHat) disclosed today, with two more admin bypasses. No fix yet. https://severitydaily.com/keycloak-cve-2026-93999-disabled-client-refresh-tokens-fgap-admin-bypasses-no-fix/
0000020
24 followersView on X

