CVE-2026-16108
- EPSS 0.19%
- Veröffentlicht 17.07.2026 16:43:14
- Zuletzt bearbeitet 06.08.2026 16:22:19
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with ...
CVE-2026-16093
- EPSS 0.18%
- Veröffentlicht 17.07.2026 16:42:52
- Zuletzt bearbeitet 09.08.2026 15:04:53
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid clien...
CVE-2026-16072
- EPSS 0.2%
- Veröffentlicht 17.07.2026 14:17:21
- Zuletzt bearbeitet 09.08.2026 14:53:29
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly...
CVE-2026-16089
- EPSS 0.14%
- Veröffentlicht 17.07.2026 14:15:43
- Zuletzt bearbeitet 09.08.2026 15:01:25
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorizati...
CVE-2026-15943
- EPSS 0.2%
- Veröffentlicht 17.07.2026 11:49:49
- Zuletzt bearbeitet 09.08.2026 14:56:07
A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to im...
CVE-2026-15945
- EPSS 0.18%
- Veröffentlicht 16.07.2026 17:36:24
- Zuletzt bearbeitet 09.08.2026 14:48:50
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not auth...
CVE-2026-1609
- EPSS 0.5%
- Veröffentlicht 16.07.2026 00:26:10
- Zuletzt bearbeitet 09.08.2026 15:10:59
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attac...
CVE-2026-14781
- EPSS 0.18%
- Veröffentlicht 05.07.2026 06:55:30
- Zuletzt bearbeitet 11.08.2026 01:13:00
A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves ...
CVE-2026-14615
- EPSS 0.32%
- Veröffentlicht 03.07.2026 15:47:08
- Zuletzt bearbeitet 11.08.2026 14:45:58
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when reque...
CVE-2026-14614
- EPSS 0.19%
- Veröffentlicht 03.07.2026 15:33:00
- Zuletzt bearbeitet 11.08.2026 15:06:15
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach...