Redhat

Build Of Keycloak

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 19.05.2026 10:52:29
  • Zuletzt bearbeitet 03.06.2026 20:04:25

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role per...

  • EPSS 0.74%
  • Veröffentlicht 19.05.2026 10:52:24
  • Zuletzt bearbeitet 15.07.2026 01:16:58

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to ...

  • EPSS 0.37%
  • Veröffentlicht 19.05.2026 10:28:24
  • Zuletzt bearbeitet 03.06.2026 19:53:45

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identi...

  • EPSS 0.3%
  • Veröffentlicht 19.05.2026 10:28:15
  • Zuletzt bearbeitet 03.06.2026 19:53:36

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belongin...

  • EPSS 0.28%
  • Veröffentlicht 19.05.2026 06:27:35
  • Zuletzt bearbeitet 23.07.2026 11:10:00

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens that should...

  • EPSS 0.39%
  • Veröffentlicht 19.05.2026 06:04:13
  • Zuletzt bearbeitet 23.07.2026 20:10:00

A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly cr...

  • EPSS 0.23%
  • Veröffentlicht 30.04.2026 14:53:09
  • Zuletzt bearbeitet 26.06.2026 08:16:25

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations —...

  • EPSS 0.23%
  • Veröffentlicht 14.04.2026 14:54:42
  • Zuletzt bearbeitet 02.06.2026 17:37:01

A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw oc...

  • EPSS 0.25%
  • Veröffentlicht 06.04.2026 08:38:36
  • Zuletzt bearbeitet 26.06.2026 08:16:22

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp` claim from a client-supplied ...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 02.04.2026 12:45:01
  • Zuletzt bearbeitet 15.07.2026 02:22:44

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even ...