CVE-2026-15573
- EPSS 0.29%
- Veröffentlicht 05.08.2026 13:50:03
- Zuletzt bearbeitet 31.08.2026 10:16:48
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or mat...
CVE-2026-16443
- EPSS 0.15%
- Veröffentlicht 05.08.2026 13:44:09
- Zuletzt bearbeitet 10.08.2026 18:52:14
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attribute...
CVE-2026-18569
- EPSS 0.16%
- Veröffentlicht 04.08.2026 05:13:08
- Zuletzt bearbeitet 10.08.2026 19:06:53
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC ident...
CVE-2026-18573
- EPSS 0.22%
- Veröffentlicht 02.08.2026 05:28:43
- Zuletzt bearbeitet 16.09.2026 19:17:09
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements...
CVE-2026-18572
- EPSS 0.18%
- Veröffentlicht 02.08.2026 05:18:58
- Zuletzt bearbeitet 16.09.2026 19:17:09
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in t...
CVE-2026-18571
- EPSS 0.25%
- Veröffentlicht 02.08.2026 05:18:50
- Zuletzt bearbeitet 16.09.2026 19:17:09
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-admini...
CVE-2026-18570
- EPSS 0.14%
- Veröffentlicht 02.08.2026 05:18:42
- Zuletzt bearbeitet 16.09.2026 19:17:09
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The is...
CVE-2026-18209
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:08:31
- Zuletzt bearbeitet 16.09.2026 19:17:08
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...
CVE-2026-18206
- EPSS 0.2%
- Veröffentlicht 31.07.2026 07:08:29
- Zuletzt bearbeitet 07.08.2026 14:54:56
A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or u...
CVE-2026-18203
- EPSS 0.18%
- Veröffentlicht 31.07.2026 07:08:26
- Zuletzt bearbeitet 07.08.2026 14:56:33
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify gr...