CVE-2026-4634
- EPSS 0.52%
- Veröffentlicht 02.04.2026 12:44:53
- Zuletzt bearbeitet 15.07.2026 02:22:43
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource con...
CVE-2026-4282
- EPSS 0.43%
- Veröffentlicht 02.04.2026 12:44:52
- Zuletzt bearbeitet 15.07.2026 02:22:39
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to th...
CVE-2026-4325
- EPSS 0.25%
- Veröffentlicht 02.04.2026 12:44:52
- Zuletzt bearbeitet 16.04.2026 20:51:22
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed acti...
CVE-2026-3872
- EPSS 0.44%
- Veröffentlicht 02.04.2026 12:37:30
- Zuletzt bearbeitet 15.07.2026 02:21:01
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft o...
CVE-2026-3121
- EPSS 0.47%
- Veröffentlicht 26.03.2026 19:13:26
- Zuletzt bearbeitet 02.04.2026 14:16:31
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over rol...
CVE-2026-3190
- EPSS 0.32%
- Veröffentlicht 26.03.2026 19:12:38
- Zuletzt bearbeitet 02.04.2026 14:16:31
A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even...
CVE-2026-4874
- EPSS 0.3%
- Veröffentlicht 26.03.2026 07:12:37
- Zuletzt bearbeitet 26.06.2026 08:16:23
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `bac...
CVE-2026-4633
- EPSS 0.32%
- Veröffentlicht 23.03.2026 10:53:35
- Zuletzt bearbeitet 01.04.2026 14:26:47
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to informa...
CVE-2026-4628
- EPSS 0.2%
- Veröffentlicht 23.03.2026 08:09:22
- Zuletzt bearbeitet 01.04.2026 14:29:05
A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs du...
CVE-2026-4366
- EPSS 0.23%
- Veröffentlicht 18.03.2026 04:02:59
- Zuletzt bearbeitet 09.06.2026 17:17:49
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintend...