Medium severity6.8NVD Advisory· Published May 19, 2026· Updated Jun 17, 2026
CVE-2026-4630
CVE-2026-4630
Description
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 26.6.2 | 26.6.2 |
Affected products
2Patches
Vulnerability mechanics
References
11- access.redhat.com/errata/RHSA-2026:19596nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:19597nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2026-4630nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdVendor AdvisoryWEB
- github.com/advisories/GHSA-c739-f6xw-6pv2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-4630ghsaADVISORY
- github.com/keycloak/keycloak/commit/0cea089bd19f5061f5fd47099fd6fb41a17d8c55ghsaWEB
- github.com/keycloak/keycloak/commit/1192267af8f16a7b722bdc2abbd3410c477388aaghsaWEB
- github.com/keycloak/keycloak/commit/4e9b17cbedb828b4afc6b62399eee317d4735234ghsaWEB
- github.com/keycloak/keycloak/issues/49115ghsaWEB
- github.com/keycloak/keycloak/pull/49121ghsaWEB
News mentions
0No linked articles in our index yet.