Description

A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token is accepted and you can continue to request new tokens for the session. As it can lead to a situation where an administrator removes the scope, and assumes that offline sessions are no longer available, but they are.

INFO

Published Date :

2025-10-23T14:19:24.752Z

Last Modified :

2026-01-20T21:04:49.198Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12110 vulnerability.

Vendors Products
Redhat
  • Build Keycloak

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact