CVE-2025-12150
Java vulnerability analysis and mitigation

Overview

CVE-2025-12150 is a WebAuthn Attestation Statement Verification Bypass vulnerability in Keycloak's WebAuthn registration component. It allows an attacker to bypass a realm's configured attestation policy by submitting an attestation object with fmt: "none", even when the realm requires direct attestation, enabling registration of untrusted or forged authenticators. Affected products include Red Hat build of Keycloak versions prior to 26.4.4 and 26.2.11, as well as Keycloak 24.0.2. The vulnerability was first disclosed on October 28, 2025, with patches released in November 2025. It carries a CVSS v3.1 base score of 3.1 (Low) (Red Hat CVE, Red Hat RHSA-2025:21370).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). During WebAuthn authenticator registration, Keycloak fails to properly enforce the realm's attestation policy when the submitted attestation object specifies fmt: "none" (no attestation). The server accepts this "none" format without rejecting it, even when the policy mandates direct attestation with a verifiable certificate chain. An attacker must have network access and induce user interaction (e.g., initiating a WebAuthn registration flow), but requires no prior privileges. The attack complexity is rated High due to the specific conditions required. A related GitHub issue tracks this flaw (Keycloak GitHub, Red Hat CVE).

Impact

Successful exploitation weakens authentication integrity on affected Keycloak realms by allowing an attacker to register a forged or untrusted authenticator device. Once registered, the attacker could use that authenticator to authenticate as a legitimate user, potentially gaining unauthorized access to protected applications and services. The impact is limited to integrity (Low), with no direct confidentiality or availability impact; however, the ability to register rogue authenticators could serve as a stepping stone for account takeover or persistent unauthorized access (Red Hat CVE, Feedly).

Exploitation steps

  1. Identify target: Locate a Keycloak realm configured to require direct WebAuthn attestation (i.e., attestation policy set to "Direct" or equivalent), running a vulnerable version (Keycloak < 26.4.4 or Red Hat build of Keycloak < 26.4.4 / < 26.2.11).
  2. Initiate WebAuthn registration: Begin the WebAuthn authenticator registration flow for a target account, either by creating a new account or accessing a registration endpoint that allows adding a new security key.
  3. Craft malicious attestation object: Prepare a WebAuthn attestation response where the fmt field is set to "none" and the attStmt is empty, bypassing the need for a valid attestation certificate chain.
  4. Submit forged registration: Send the crafted attestation object to the Keycloak WebAuthn registration endpoint. Due to the improper verification flaw, the server accepts the fmt: "none" attestation without enforcing the direct attestation policy.
  5. Authenticate with forged authenticator: Use the newly registered (forged) authenticator to authenticate to the Keycloak realm, gaining unauthorized access to protected resources (Red Hat CVE, Keycloak GitHub).

Indicators of compromise

  • Logs: Keycloak audit/event logs showing WebAuthn authenticator registration events with attestation format "none" on realms configured to require direct attestation; unexpected new authenticator registrations for existing user accounts.
  • Application Logs: Keycloak server logs (server.log) containing WebAuthn registration completions without corresponding attestation certificate validation entries.
  • Network: HTTP POST requests to Keycloak's WebAuthn registration endpoints (e.g., /realms/{realm}/webauthn-register) containing attestation objects with fmt: "none" and empty attStmt from unexpected or unknown client IPs.
  • Administrative Console: Presence of newly registered authenticators for user accounts that were not expected or authorized, particularly those lacking attestation metadata or device information.

Mitigation and workarounds

Red Hat has released patches addressing this vulnerability. Administrators should upgrade to the following fixed versions:

  • Keycloak: Update to version 26.4.4 or later.
  • Red Hat build of Keycloak 26.4: Apply patch 26.4.4-1 or later (RHSA-2025:21370, RHSA-2025:21371).
  • Red Hat build of Keycloak 26.2: Apply patch 26.2.11-1 or later (RHSA-2025:22088, RHSA-2025:22089).

As an interim measure, administrators should review existing WebAuthn registrations on realms with direct attestation requirements to identify any suspicious or forged authenticators. Implementing additional monitoring on WebAuthn attestation failures and registration events is also recommended (Red Hat RHSA-2025:21370, Red Hat RHSA-2025:22089).

Community reactions

Red Hat classified this vulnerability as "Moderate" severity in its security advisories, bundling the fix with several other Keycloak security issues in the 26.4.4 and 26.2.11 releases. The vulnerability was tracked via a Red Hat Bugzilla entry and a Keycloak GitHub issue. No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability database aggregators (Red Hat RHSA-2025:21370, Keycloak GitHub).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management