Redhat

Keycloak

266 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 24.07.2026 13:41:09
  • Zuletzt bearbeitet 19.08.2026 04:16:57

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforceme...

  • EPSS 0.21%
  • Veröffentlicht 17.07.2026 16:43:54
  • Zuletzt bearbeitet 06.08.2026 16:25:57

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive confi...

  • EPSS 0.2%
  • Veröffentlicht 17.07.2026 16:43:50
  • Zuletzt bearbeitet 06.08.2026 16:31:55

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were o...

  • EPSS 0.19%
  • Veröffentlicht 17.07.2026 16:43:16
  • Zuletzt bearbeitet 06.08.2026 16:24:48

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker...

  • EPSS 0.19%
  • Veröffentlicht 17.07.2026 16:43:14
  • Zuletzt bearbeitet 06.08.2026 16:22:19

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with ...

  • EPSS 0.18%
  • Veröffentlicht 17.07.2026 16:42:52
  • Zuletzt bearbeitet 09.08.2026 15:04:53

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid clien...

  • EPSS 0.2%
  • Veröffentlicht 17.07.2026 14:17:21
  • Zuletzt bearbeitet 09.08.2026 14:53:29

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly...

  • EPSS 0.14%
  • Veröffentlicht 17.07.2026 14:15:43
  • Zuletzt bearbeitet 09.08.2026 15:01:25

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorizati...

  • EPSS 0.2%
  • Veröffentlicht 17.07.2026 11:49:49
  • Zuletzt bearbeitet 09.08.2026 14:56:07

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to im...

  • EPSS 0.18%
  • Veröffentlicht 16.07.2026 17:36:24
  • Zuletzt bearbeitet 09.08.2026 14:48:50

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not auth...