5.4
CVE-2026-16071
- EPSS 0.18%
- Veröffentlicht 05.08.2026 13:50:54
- Zuletzt bearbeitet 10.08.2026 18:37:16
- CVE-Watchlists
- Unerledigt
Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
Mögliche Gegenmaßnahme
Keycloak Server: Install latest version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Build Of Keycloak Version >= 26.4 < 26.4.14
Redhat ≫ Build Of Keycloak Version >= 26.6 < 26.6.5
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemKeycloak
≫
Produkt
Keycloak Server
Version
< 26.4.14
Version
< 26.6.5
Version
< 26.7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://access.redhat.com/security/cve/CVE-2026-16071
https://bugzilla.redhat.com/show_bug.cgi?id=2501720
https://access.redhat.com/errata/RHSA-2026:50846
https://access.redhat.com/errata/RHSA-2026:50847
https://access.redhat.com/errata/RHSA-2026:50848
https://access.redhat.com/errata/RHSA-2026:50849
https://github.com/keycloak/keycloak/security/advisories/GHSA-hmr6-pxx9-552p