Redhat

Build Of Keycloak

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 06:48:14
  • Zuletzt bearbeitet 07.08.2026 18:11:31

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker w...

  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 06:38:25
  • Zuletzt bearbeitet 07.08.2026 18:05:48

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured w...

  • EPSS 0.13%
  • Veröffentlicht 31.07.2026 06:38:18
  • Zuletzt bearbeitet 07.08.2026 17:54:23

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the...

  • EPSS 0.29%
  • Veröffentlicht 29.07.2026 08:34:47
  • Zuletzt bearbeitet 07.08.2026 21:05:35

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without havi...

  • EPSS 0.29%
  • Veröffentlicht 29.07.2026 08:34:44
  • Zuletzt bearbeitet 11.08.2026 01:35:13

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by ...

Medienbericht
  • EPSS 0.2%
  • Veröffentlicht 24.07.2026 14:06:21
  • Zuletzt bearbeitet 10.08.2026 13:08:57

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission t...

  • EPSS 0.24%
  • Veröffentlicht 24.07.2026 13:41:09
  • Zuletzt bearbeitet 19.08.2026 04:16:57

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforceme...

  • EPSS 0.21%
  • Veröffentlicht 17.07.2026 16:43:54
  • Zuletzt bearbeitet 06.08.2026 16:25:57

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive confi...

  • EPSS 0.2%
  • Veröffentlicht 17.07.2026 16:43:50
  • Zuletzt bearbeitet 06.08.2026 16:31:55

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were o...

  • EPSS 0.19%
  • Veröffentlicht 17.07.2026 16:43:16
  • Zuletzt bearbeitet 06.08.2026 16:24:48

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker...