Bitnami package
keycloak
pkg:bitnami/keycloak
Vulnerabilities (52)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-15571 | Hig | 7.3 | < 26.7.2 | 26.7.2 | Aug 18, 2026 | A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by | |
| CVE-2026-18963 | Cri | 9.1 | < 26.7.2 | 26.7.2 | Aug 18, 2026 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needi | |
| CVE-2026-16442 | Hig | 7.4 | >= 26.4.0, < 26.4.14 | 26.4.14 | Aug 5, 2026 | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an at | |
| CVE-2026-15572 | Hig | 8.8 | >= 26.4.0, < 26.4.14 | 26.4.14 | Aug 5, 2026 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's confi | |
| CVE-2026-16102 | Hig | 8.1 | >= 26.4.0, < 26.4.14 | 26.4.14 | Aug 5, 2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locat | |
| CVE-2026-16100 | Med | 6.5 | >= 26.6.0, < 26.6.5 | 26.6.5 | Aug 5, 2026 | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, | |
| CVE-2026-16071 | Med | 5.4 | >= 26.4.0, < 26.4.14 | 26.4.14 | Aug 5, 2026 | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the sy | |
| CVE-2026-15573 | Hig | 8.1 | >= 26.4.0, < 26.4.14 | 26.4.14 | Aug 5, 2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an at | |
| CVE-2026-16443 | Hig | 7.4 | >= 26.4.0, < 26.4.14 | 26.4.14 | Aug 5, 2026 | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorre | |
| CVE-2026-17048 | Med | 5.5 | < 26.7.2 | 26.7.2 | Jul 24, 2026 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator | |
| CVE-2026-15945 | Med | 4.3 | < 26.7.2 | 26.7.2 | Jul 16, 2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fo | |
| CVE-2026-1609 | Hig | 8.1 | >= 26.5.2, < 26.5.3 | 26.5.3 | Jul 16, 2026 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can ex | |
| CVE-2026-14615 | Med | 4.3 | >= 26.4.0, < 26.4.14 | 26.4.14 | Jul 3, 2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. T | |
| CVE-2026-14614 | Med | 5.4 | >= 26.4.0, < 26.4.14 | 26.4.14 | Jul 3, 2026 | A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scope | |
| CVE-2026-14613 | Med | 4.3 | < 26.7.2 | 26.7.2 | Jul 3, 2026 | A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a sp | |
| CVE-2026-11800 | Hig | 8.1 | >= 26.6.0, < 26.6.4 | 26.6.4 | Jun 25, 2026 | A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enable | |
| CVE-2026-9800 | Hig | 8.1 | >= 26.4.0, < 26.4.13 | 26.4.13 | Jun 25, 2026 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, e | |
| CVE-2026-9799 | Med | 4.6 | >= 26.4.0, < 26.4.13 | 26.4.13 | Jun 25, 2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain una | |
| CVE-2026-9705 | Med | 6.5 | >= 26.4.0, < 26.4.13 | 26.4.13 | Jun 25, 2026 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, al | |
| CVE-2026-9099 | Hig | 7.7 | >= 26.4.0, < 26.4.13 | 26.4.13 | Jun 25, 2026 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is en |
- affected < 26.7.2fixed 26.7.2
A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by
- affected < 26.7.2fixed 26.7.2
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needi
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an at
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's confi
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locat
- affected >= 26.6.0, < 26.6.5fixed 26.6.5
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs,
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the sy
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an at
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorre
- affected < 26.7.2fixed 26.7.2
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator
- affected < 26.7.2fixed 26.7.2
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fo
- affected >= 26.5.2, < 26.5.3fixed 26.5.3
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can ex
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. T
- affected >= 26.4.0, < 26.4.14fixed 26.4.14
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scope
- affected < 26.7.2fixed 26.7.2
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a sp
- affected >= 26.6.0, < 26.6.4fixed 26.6.4
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enable
- affected >= 26.4.0, < 26.4.13fixed 26.4.13
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, e
- affected >= 26.4.0, < 26.4.13fixed 26.4.13
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain una
- affected >= 26.4.0, < 26.4.13fixed 26.4.13
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, al
- affected >= 26.4.0, < 26.4.13fixed 26.4.13
A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is en
Page 1 of 3