CVE-2026-18214
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:08:26
- Zuletzt bearbeitet 07.08.2026 18:19:27
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does...
CVE-2026-18211
- EPSS 0.18%
- Veröffentlicht 31.07.2026 07:08:24
- Zuletzt bearbeitet 07.08.2026 14:30:12
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Du...
CVE-2026-18208
- EPSS 0.2%
- Veröffentlicht 31.07.2026 07:08:20
- Zuletzt bearbeitet 07.08.2026 14:47:32
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential cli...
CVE-2026-16105
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:03:36
- Zuletzt bearbeitet 07.08.2026 14:59:14
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated admin...
CVE-2026-18215
- EPSS 0.19%
- Veröffentlicht 31.07.2026 06:48:14
- Zuletzt bearbeitet 07.08.2026 18:11:31
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker w...
CVE-2026-18217
- EPSS 0.19%
- Veröffentlicht 31.07.2026 06:38:25
- Zuletzt bearbeitet 07.08.2026 18:05:48
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured w...
CVE-2026-18218
- EPSS 0.13%
- Veröffentlicht 31.07.2026 06:38:18
- Zuletzt bearbeitet 07.08.2026 17:54:23
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the...
CVE-2026-18201
- EPSS 0.29%
- Veröffentlicht 29.07.2026 08:34:47
- Zuletzt bearbeitet 07.08.2026 21:05:35
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without havi...
CVE-2026-18207
- EPSS 0.29%
- Veröffentlicht 29.07.2026 08:34:44
- Zuletzt bearbeitet 11.08.2026 01:35:13
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by ...
CVE-2026-17059
- EPSS 0.2%
- Veröffentlicht 24.07.2026 14:06:21
- Zuletzt bearbeitet 10.08.2026 13:08:57
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission t...