VYPR

Bitnami package

keycloak

pkg:bitnami/keycloak

Vulnerabilities (52)

  • CVE-2026-15571HigAug 18, 2026
    affected < 26.7.2fixed 26.7.2

    A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by

  • CVE-2026-18963CriAug 18, 2026
    affected < 26.7.2fixed 26.7.2

    A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needi

  • CVE-2026-16442HigAug 5, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an at

  • CVE-2026-15572HigAug 5, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's confi

  • CVE-2026-16102HigAug 5, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locat

  • CVE-2026-16100MedAug 5, 2026
    affected >= 26.6.0, < 26.6.5fixed 26.6.5

    A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs,

  • CVE-2026-16071MedAug 5, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the sy

  • CVE-2026-15573HigAug 5, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an at

  • CVE-2026-16443HigAug 5, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorre

  • CVE-2026-17048MedJul 24, 2026
    affected < 26.7.2fixed 26.7.2

    A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator

  • CVE-2026-15945MedJul 16, 2026
    affected < 26.7.2fixed 26.7.2

    A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fo

  • CVE-2026-1609HigJul 16, 2026
    affected >= 26.5.2, < 26.5.3fixed 26.5.3

    A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can ex

  • CVE-2026-14615MedJul 3, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. T

  • CVE-2026-14614MedJul 3, 2026
    affected >= 26.4.0, < 26.4.14fixed 26.4.14

    A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scope

  • CVE-2026-14613MedJul 3, 2026
    affected < 26.7.2fixed 26.7.2

    A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a sp

  • CVE-2026-11800HigJun 25, 2026
    affected >= 26.6.0, < 26.6.4fixed 26.6.4

    A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enable

  • CVE-2026-9800HigJun 25, 2026
    affected >= 26.4.0, < 26.4.13fixed 26.4.13

    A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, e

  • CVE-2026-9799MedJun 25, 2026
    affected >= 26.4.0, < 26.4.13fixed 26.4.13

    A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain una

  • CVE-2026-9705MedJun 25, 2026
    affected >= 26.4.0, < 26.4.13fixed 26.4.13

    A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, al

  • CVE-2026-9099HigJun 25, 2026
    affected >= 26.4.0, < 26.4.13fixed 26.4.13

    A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is en

Page 1 of 3