Redhat

Build Of Keycloak

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 25.06.2026 16:16:27
  • Zuletzt bearbeitet 06.08.2026 13:18:26

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied pag...

  • EPSS 0.3%
  • Veröffentlicht 11.06.2026 16:47:11
  • Zuletzt bearbeitet 11.08.2026 12:58:09

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role...

  • EPSS 0.3%
  • Veröffentlicht 28.05.2026 04:47:10
  • Zuletzt bearbeitet 26.06.2026 08:16:35

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, ...

  • EPSS 0.42%
  • Veröffentlicht 28.05.2026 04:47:10
  • Zuletzt bearbeitet 26.06.2026 08:16:35

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration e...

  • EPSS 0.48%
  • Veröffentlicht 28.05.2026 04:42:10
  • Zuletzt bearbeitet 26.06.2026 08:16:34

A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vu...

  • EPSS 0.35%
  • Veröffentlicht 28.05.2026 04:37:09
  • Zuletzt bearbeitet 20.08.2026 01:16:54

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchan...

  • EPSS 0.22%
  • Veröffentlicht 28.05.2026 04:27:08
  • Zuletzt bearbeitet 19.08.2026 04:17:43

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges t...

  • EPSS 0.35%
  • Veröffentlicht 28.05.2026 03:49:10
  • Zuletzt bearbeitet 15.07.2026 01:17:10

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scop...

  • EPSS 0.33%
  • Veröffentlicht 28.05.2026 03:44:20
  • Zuletzt bearbeitet 26.06.2026 08:16:27

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs....

  • EPSS 0.27%
  • Veröffentlicht 28.05.2026 03:44:18
  • Zuletzt bearbeitet 26.06.2026 08:16:27

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, ...