cbcvebase.

Redhat Build Of Keycloak vulnerabilities

32 known vulnerabilities affecting redhat/build_of_keycloak.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH15MEDIUM15LOW2

Vulnerabilities

Page 1 of 2
CVE-2026-3047P2HIGHCVSS 8.8v26.2v26.2.14+2 more2026-03-05
CVE-2026-3047 [HIGH] CWE-305 CVE-2026-3047: A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SA A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled client
nvd
CVE-2026-9800P3HIGHCVSS 8.1≥ 26.4, < 26.4.13≥ 26.6, ≤ 26.6.42026-06-25
CVE-2026-9800 [HIGH] CWE-1025 CVE-2026-9800: A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to by A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unautho
nvd
CVE-2026-11800P3HIGHCVSS 8.1≥ 26.6, < 26.6.42026-06-25
CVE-2026-11800 [HIGH] CWE-347 CVE-2026-11800: A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Gr A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected I
nvd
CVE-2026-4282P3HIGHCVSS 7.4v26.2v26.2.15+2 more2026-04-02
CVE-2026-4282 [HIGH] CWE-653 CVE-2026-4282: A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper ty A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
nvd
CVE-2026-3009P3HIGHCVSS 8.1v26.4v26.4.102026-03-05
CVE-2026-3009 [HIGH] CWE-863 CVE-2026-3009: A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control e
nvd
CVE-2026-4636P3HIGHCVSS 8.1v26.2v26.2.15+2 more2026-04-02
CVE-2026-4636 [HIGH] CWE-551 CVE-2026-4636: A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Man A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permi
nvd
CVE-2026-9099P3HIGHCVSS 7.7≥ 26.4, < 26.4.13≥ 26.6, < 26.6.42026-06-25
CVE-2026-9099 [HIGH] CWE-639 CVE-2026-9099: A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management rights over a single low-privilege group
nvd
CVE-2026-7507P3HIGHCVSS 7.5≥ 26.4, < 26.4.122026-05-19
CVE-2026-7507 [HIGH] CWE-290 CVE-2026-7507: A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection
nvd
CVE-2026-7307P3HIGHCVSS 7.5≥ 26.4, < 26.4.122026-05-19
CVE-2026-7307 [HIGH] CWE-1286 CVE-2026-7307: A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML in A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
nvd
CVE-2026-4634P3HIGHCVSS 7.5v26.2v26.2.15+2 more2026-04-02
CVE-2026-4634 [HIGH] CWE-1050 CVE-2026-4634: A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keyclo
nvd
CVE-2026-9086P3HIGHCVSS 7.3≥ 26.4, < 26.4.13≥ 26.6, < 26.6.42026-06-25
CVE-2026-9086 [HIGH] CWE-79 CVE-2026-9086: A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those w A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malicious client with a specially crafted redirect URI using a case-insensitive `
nvd
CVE-2026-4630P3MEDIUMCVSS 6.8≥ 26.4, < 26.4.122026-05-19
CVE-2026-4630 [MEDIUM] CWE-639 CVE-2026-4630: A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Refere A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This
nvd
CVE-2026-7504P3HIGHCVSS 8.1≥ 26.4, < 26.4.122026-05-19
CVE-2026-7504 [HIGH] CWE-601 CVE-2026-7504: A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malici A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further attacks. This vulnerability specifically affects Keycloak clien
nvd
CVE-2026-3872P3HIGHCVSS 7.3v26.2v26.2.15+2 more2026-04-02
CVE-2026-3872 [HIGH] CWE-601 CVE-2026-3872: A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same w A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.
nvd
CVE-2026-37982P3MEDIUMCVSS 6.8≥ 26.4, < 26.4.122026-05-19
CVE-2026-37982 [MEDIUM] CWE-294 CVE-2026-37982: A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay ` A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a h
nvd
CVE-2026-37979P3MEDIUMCVSS 6.5≥ 26.4, < 26.4.122026-05-19
CVE-2026-37979 [MEDIUM] CWE-284 CVE-2026-37979: A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of
nvd
CVE-2026-7571P3HIGHCVSS 7.1≥ 26.4, < 26.4.122026-05-19
CVE-2026-7571 [HIGH] CWE-472 CVE-2026-7571: A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be available. This vulnerability can also
nvd
CVE-2026-9705P3MEDIUMCVSS 6.5≥ 26.4, < 26.4.13≥ 26.6, < 26.6.42026-06-25
CVE-2026-9705 [MEDIUM] CWE-613 CVE-2026-9705: A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previous A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain p
nvd
CVE-2024-4629P3MEDIUMCVSS 6.5≥ 22.0, < 22.0122024-09-03
CVE-2024-4629 [MEDIUM] CWE-837 CVE-2024-4629: A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection b A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses
nvd
CVE-2024-7341P3HIGHCVSS 7.1≥ 22.0, < 22.0.12≥ 24.0, < 24.0.72024-09-09
CVE-2024-7341 [HIGH] CWE-384 CVE-2024-7341: A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID an A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.
nvd
Redhat Build Of Keycloak vulnerabilities | cvebase