CVE-2026-97177
- EPSS 0.24%
- Veröffentlicht 24.09.2026 05:47:57
- Zuletzt bearbeitet 24.09.2026 21:00:46
A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a de...
CVE-2026-97176
- EPSS 0.17%
- Veröffentlicht 24.09.2026 05:47:52
- Zuletzt bearbeitet 26.09.2026 23:16:43
A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session a...
CVE-2026-96445
- EPSS 0.24%
- Veröffentlicht 23.09.2026 11:12:46
- Zuletzt bearbeitet 24.09.2026 14:51:56
A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to ...
CVE-2026-96446
- EPSS 0.18%
- Veröffentlicht 23.09.2026 11:03:50
- Zuletzt bearbeitet 26.09.2026 23:16:40
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in...
CVE-2026-95503
- EPSS 0.13%
- Veröffentlicht 22.09.2026 07:43:29
- Zuletzt bearbeitet 22.09.2026 19:37:36
A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Distribution Ce...
CVE-2026-94218
- EPSS 0.2%
- Veröffentlicht 21.09.2026 06:45:34
- Zuletzt bearbeitet 22.09.2026 19:37:36
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup...
CVE-2026-94217
- EPSS 0.14%
- Veröffentlicht 21.09.2026 06:45:27
- Zuletzt bearbeitet 24.09.2026 14:18:20
A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system incorrectly mer...
CVE-2026-94215
- EPSS 0.18%
- Veröffentlicht 21.09.2026 06:03:43
- Zuletzt bearbeitet 22.09.2026 19:37:36
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the cli...
CVE-2026-94213
- EPSS 0.23%
- Veröffentlicht 21.09.2026 06:03:37
- Zuletzt bearbeitet 22.09.2026 19:37:36
A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to spe...
CVE-2026-94001
- EPSS 0.25%
- Veröffentlicht 19.09.2026 14:11:53
- Zuletzt bearbeitet 22.09.2026 19:37:36
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows a delegated ...