Redhat Build Of Keycloak vulnerabilities
32 known vulnerabilities affecting redhat/build_of_keycloak.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH15MEDIUM15LOW2
Vulnerabilities
Page 2 of 2
CVE-2026-4325P4MEDIUMCVSS 5.3v26.2v26.2.15+2 more2026-04-02
CVE-2026-4325 [MEDIUM] CWE-653 CVE-2026-4325: A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper ty
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise.
nvd
CVE-2026-9083P4MEDIUMCVSS 4.9≥ 26.4, < 26.4.13≥ 26.6, < 26.6.42026-06-25
CVE-2026-9083 [MEDIUM] CWE-22 CVE-2026-9083: A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vu
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak proce
nvd
CVE-2026-2575P4MEDIUMCVSS 5.3≥ 26.4, < 26.4.102026-03-18
CVE-2026-2575 [MEDIUM] CWE-409 CVE-2026-2575: A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level De
A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulne
nvd
CVE-2026-37978P4MEDIUMCVSS 4.9fixed in 26.4.122026-05-19
CVE-2026-37978 [MEDIUM] CWE-639 CVE-2026-37978: A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized visibility into user identities
nvd
CVE-2026-0871P4MEDIUMCVSS 4.9fixed in 26.4.92026-02-27
CVE-2026-0871 [MEDIUM] CWE-266 CVE-2026-0871: A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only a
A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
nvd
CVE-2025-3910P4MEDIUMCVSS 5.4≥ 26.0, < 26.0.112025-04-29
CVE-2025-3910 [MEDIUM] CWE-287 CVE-2025-3910: A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumvent
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
nvd
CVE-2026-37981P4MEDIUMCVSS 4.3≥ 26.4, < 26.4.122026-05-19
CVE-2026-37981 [MEDIUM] CWE-1220 CVE-2026-37981: A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lo
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames o
nvd
CVE-2024-7260P4MEDIUMCVSS 6.1fixed in 24.0.72024-09-09
CVE-2024-7260 [MEDIUM] CWE-601 CVE-2024-7260: An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed whe
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is safe, when, in fact, it redirects to a malicious server. This issue can result
nvd
CVE-2026-9799P4MEDIUMCVSS 4.6≥ 26.4, < 26.4.13≥ 26.6, < 26.6.42026-06-25
CVE-2026-9799 [MEDIUM] CWE-639 CVE-2026-9799: A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Ac
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource s
nvd
CVE-2024-7318P4MEDIUMCVSS 4.8≥ 22.0, < 24.0.72024-09-09
CVE-2024-7318 [MEDIUM] CWE-324 CVE-2024-7318: A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when th
A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute.
A one time passcode that is valid longer than its expiration time incre
nvd
CVE-2025-12150P4LOWCVSS 3.1fixed in 26.4.42026-02-27
CVE-2025-12150 [LOW] CWE-347 CVE-2025-12150: A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacke
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authenticat
nvd
CVE-2026-3911P4LOWCVSS 2.7v26.4v26.4.112026-03-11
CVE-2026-3911 [LOW] CWE-359 CVE-2026-3911: A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnera
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
nvd
← Previous2 / 2