CVE-2026-107121
- EPSS 0.08%
- Veröffentlicht 07.10.2026 07:42:04
- Zuletzt bearbeitet 07.10.2026 14:47:21
A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if th...
CVE-2026-105305
- EPSS 0.19%
- Veröffentlicht 06.10.2026 07:33:32
- Zuletzt bearbeitet 06.10.2026 15:09:20
A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to chec...
CVE-2026-105302
- EPSS 0.2%
- Veröffentlicht 05.10.2026 06:16:58
- Zuletzt bearbeitet 06.10.2026 15:09:20
A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federate...
CVE-2026-105306
- EPSS 0.22%
- Veröffentlicht 05.10.2026 06:16:58
- Zuletzt bearbeitet 06.10.2026 15:09:20
A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An at...
- EPSS 0.12%
- Veröffentlicht 05.10.2026 05:35:52
- Zuletzt bearbeitet 06.10.2026 15:09:20
A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attack...
CVE-2026-103884
- EPSS 0.21%
- Veröffentlicht 01.10.2026 17:16:21
- Zuletzt bearbeitet 01.10.2026 20:36:15
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially cr...
CVE-2026-101333
- EPSS 0.23%
- Veröffentlicht 28.09.2026 14:38:15
- Zuletzt bearbeitet 28.09.2026 16:26:58
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send reques...
CVE-2026-96448
- EPSS 0.24%
- Veröffentlicht 25.09.2026 07:39:51
- Zuletzt bearbeitet 26.09.2026 23:16:40
A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user....
CVE-2026-97846
- EPSS 0.14%
- Veröffentlicht 25.09.2026 06:16:38
- Zuletzt bearbeitet 25.09.2026 14:17:26
Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard Token Exchan...
CVE-2026-97311
- EPSS 0.25%
- Veröffentlicht 24.09.2026 11:28:39
- Zuletzt bearbeitet 24.09.2026 21:00:46
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a del...