Mmastodon TechnologyCybersecurity first seen 12 h ago, last 12 h ago, peak #11
Keycloak flaw lets stolen passwords bypass mandatory MFA
Original: CVE-2026-105305 affects Red Hat build of Keycloak. The OIDC Device Authorization Grant flow does not enforce a client's
A vulnerability tracked as CVE-2026-105305 affects the Red Hat build of Keycloak. The OIDC Device Authorization Grant flow fails to enforce a client's minimum authentication level, meaning a stolen password could bypass mandatory multi-factor authentication and gain access to the Admin REST API. No exploitation has been confirmed, and Red Hat has a fix available. Security practitioners are sharing the advisory and urging admins to patch promptly.
Why now: Security teams are alerting each other to a newly disclosed MFA-bypass vulnerability with an available fix.
Red HatKeycloakCVE-2026-105305
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1215019