Redhat

Build Of Keycloak

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 03.07.2026 15:16:44
  • Zuletzt bearbeitet 19.08.2026 04:16:56

A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administra...

  • EPSS 0.25%
  • Veröffentlicht 30.06.2026 12:00:28
  • Zuletzt bearbeitet 01.07.2026 20:26:45

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can ...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 30.06.2026 12:00:28
  • Zuletzt bearbeitet 05.08.2026 19:17:31

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject ...

  • EPSS 0.22%
  • Veröffentlicht 30.06.2026 11:48:26
  • Zuletzt bearbeitet 05.08.2026 19:17:21

A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for...

  • EPSS 0.18%
  • Veröffentlicht 25.06.2026 20:57:05
  • Zuletzt bearbeitet 15.07.2026 02:18:03

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthori...

  • EPSS 0.52%
  • Veröffentlicht 25.06.2026 16:17:49
  • Zuletzt bearbeitet 01.07.2026 17:22:17

A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator t...

  • EPSS 0.17%
  • Veröffentlicht 25.06.2026 16:17:48
  • Zuletzt bearbeitet 01.07.2026 18:37:39

A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. Th...

  • EPSS 0.27%
  • Veröffentlicht 25.06.2026 16:17:46
  • Zuletzt bearbeitet 01.07.2026 18:38:08

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This ...

  • EPSS 0.42%
  • Veröffentlicht 25.06.2026 16:16:46
  • Zuletzt bearbeitet 15.07.2026 01:17:08

A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is a...

  • EPSS 0.29%
  • Veröffentlicht 25.06.2026 16:16:43
  • Zuletzt bearbeitet 15.07.2026 01:17:08

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin...