CVE-2026-18570
- EPSS 0.14%
- Veröffentlicht 02.08.2026 05:18:42
- Zuletzt bearbeitet 16.09.2026 19:17:09
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The is...
CVE-2026-18209
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:08:31
- Zuletzt bearbeitet 16.09.2026 19:17:08
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...
CVE-2026-18211
- EPSS 0.18%
- Veröffentlicht 31.07.2026 07:08:24
- Zuletzt bearbeitet 07.08.2026 14:30:12
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Du...
CVE-2026-18208
- EPSS 0.2%
- Veröffentlicht 31.07.2026 07:08:20
- Zuletzt bearbeitet 07.08.2026 14:47:32
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential cli...
CVE-2026-16105
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:03:36
- Zuletzt bearbeitet 16.09.2026 19:17:07
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated admin...
CVE-2026-17048
- EPSS 0.24%
- Veröffentlicht 24.07.2026 13:41:09
- Zuletzt bearbeitet 19.08.2026 04:16:57
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforceme...
CVE-2026-16104
- EPSS 0.21%
- Veröffentlicht 17.07.2026 16:43:54
- Zuletzt bearbeitet 16.09.2026 19:17:07
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive confi...
CVE-2026-16108
- EPSS 0.19%
- Veröffentlicht 17.07.2026 16:43:14
- Zuletzt bearbeitet 16.09.2026 19:17:07
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with ...
CVE-2026-16093
- EPSS 0.18%
- Veröffentlicht 17.07.2026 16:42:52
- Zuletzt bearbeitet 16.09.2026 19:17:07
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid clien...
CVE-2026-15945
- EPSS 0.18%
- Veröffentlicht 16.07.2026 17:36:24
- Zuletzt bearbeitet 16.09.2026 19:17:06
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not auth...