Business Logic Errors in org.keycloak:keycloak-services
CVE-2025-14559
- org.keycloak:keycloak-services
Summary
A flaw was found in the keycloak-services component of Keycloak. Affected versions are prior to 26.5.2. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privileged client invokes the token exchange flow.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- HIGH
- HIGH
- NONE
CWE-840 - Business Logic Errors
Weaknesses in this category identify some of the underlying problems that commonly allow attackers to manipulate the business logic of an application. Errors in business logic can be devastating to an entire application. They can be difficult to find automatically, since they typically involve legitimate use of the application's functionality. However, many business logic errors can exhibit patterns that are similar to well-understood implementation and design weaknesses.
References
Advisory Timeline
- Published