CVE-2026-18572
- EPSS 0.18%
- Veröffentlicht 02.08.2026 05:18:58
- Zuletzt bearbeitet 07.08.2026 18:24:33
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in t...
CVE-2026-18571
- EPSS 0.25%
- Veröffentlicht 02.08.2026 05:18:50
- Zuletzt bearbeitet 07.08.2026 18:30:35
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-admini...
CVE-2026-18570
- EPSS 0.14%
- Veröffentlicht 02.08.2026 05:18:42
- Zuletzt bearbeitet 07.08.2026 18:35:30
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The is...
CVE-2026-18209
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:08:31
- Zuletzt bearbeitet 07.08.2026 14:35:42
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...
CVE-2026-18206
- EPSS 0.2%
- Veröffentlicht 31.07.2026 07:08:29
- Zuletzt bearbeitet 07.08.2026 14:54:56
A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or u...
CVE-2026-18203
- EPSS 0.18%
- Veröffentlicht 31.07.2026 07:08:26
- Zuletzt bearbeitet 07.08.2026 14:56:33
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify gr...
CVE-2026-18214
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:08:26
- Zuletzt bearbeitet 07.08.2026 18:19:27
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does...
CVE-2026-18211
- EPSS 0.18%
- Veröffentlicht 31.07.2026 07:08:24
- Zuletzt bearbeitet 07.08.2026 14:30:12
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Du...
CVE-2026-18208
- EPSS 0.2%
- Veröffentlicht 31.07.2026 07:08:20
- Zuletzt bearbeitet 07.08.2026 14:47:32
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential cli...
CVE-2026-16105
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:03:36
- Zuletzt bearbeitet 07.08.2026 14:59:14
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated admin...