
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12150 is a WebAuthn Attestation Statement Verification Bypass vulnerability in Keycloak's WebAuthn registration component. It allows an attacker to bypass a realm's configured attestation policy by submitting an attestation object with fmt: "none", even when the realm requires direct attestation, enabling registration of untrusted or forged authenticators. Affected products include Red Hat build of Keycloak versions prior to 26.4.4 and 26.2.11, as well as Keycloak 24.0.2. The vulnerability was first disclosed on October 28, 2025, with patches released in November 2025. It carries a CVSS v3.1 base score of 3.1 (Low) (Red Hat CVE, Red Hat RHSA-2025:21370).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). During WebAuthn authenticator registration, Keycloak fails to properly enforce the realm's attestation policy when the submitted attestation object specifies fmt: "none" (no attestation). The server accepts this "none" format without rejecting it, even when the policy mandates direct attestation with a verifiable certificate chain. An attacker must have network access and induce user interaction (e.g., initiating a WebAuthn registration flow), but requires no prior privileges. The attack complexity is rated High due to the specific conditions required. A related GitHub issue tracks this flaw (Keycloak GitHub, Red Hat CVE).
Successful exploitation weakens authentication integrity on affected Keycloak realms by allowing an attacker to register a forged or untrusted authenticator device. Once registered, the attacker could use that authenticator to authenticate as a legitimate user, potentially gaining unauthorized access to protected applications and services. The impact is limited to integrity (Low), with no direct confidentiality or availability impact; however, the ability to register rogue authenticators could serve as a stepping stone for account takeover or persistent unauthorized access (Red Hat CVE, Feedly).
fmt field is set to "none" and the attStmt is empty, bypassing the need for a valid attestation certificate chain.fmt: "none" attestation without enforcing the direct attestation policy."none" on realms configured to require direct attestation; unexpected new authenticator registrations for existing user accounts.server.log) containing WebAuthn registration completions without corresponding attestation certificate validation entries./realms/{realm}/webauthn-register) containing attestation objects with fmt: "none" and empty attStmt from unexpected or unknown client IPs.Red Hat has released patches addressing this vulnerability. Administrators should upgrade to the following fixed versions:
As an interim measure, administrators should review existing WebAuthn registrations on realms with direct attestation requirements to identify any suspicious or forged authenticators. Implementing additional monitoring on WebAuthn attestation failures and registration events is also recommended (Red Hat RHSA-2025:21370, Red Hat RHSA-2025:22089).
Red Hat classified this vulnerability as "Moderate" severity in its security advisories, bundling the fix with several other Keycloak security issues in the 26.4.4 and 26.2.11 releases. The vulnerability was tracked via a Red Hat Bugzilla entry and a Keycloak GitHub issue. No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability database aggregators (Red Hat RHSA-2025:21370, Keycloak GitHub).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."