Bitnami package
keycloak
pkg:bitnami/keycloak
Vulnerabilities (52)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-9086 | Hig | 7.3 | >= 26.4.0, < 26.4.13 | 26.4.13 | Jun 25, 2026 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malic | |
| CVE-2026-9083 | Med | 4.9 | >= 26.4.0, < 26.4.13 | 26.4.13 | Jun 25, 2026 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem p | |
| CVE-2026-11986 | Med | 4.9 | >= 26.6.0, < 26.6.5 | 26.6.5 | Jun 11, 2026 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a deleg | |
| CVE-2026-7571 | Hig | 7.1 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain | |
| CVE-2026-7507 | Hig | 7.5 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart | |
| CVE-2026-7504 | Hig | 8.1 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitat | |
| CVE-2026-7307 | Hig | 7.5 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) wher | |
| CVE-2026-4630 | Med | 6.8 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server w | |
| CVE-2026-37982 | Med | 6.8 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authentica | |
| CVE-2026-37981 | Med | 4.3 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for a | |
| CVE-2026-37979 | Med | 6.5 | >= 26.4.0, < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims | |
| CVE-2026-37978 | Med | 4.9 | < 26.4.12 | 26.4.12 | May 19, 2026 | A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable informati | |
| CVE-2026-4636 | Hig | 8.1 | >= 26.2.0, < 26.2.1 | 26.2.1 | Apr 2, 2026 | A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an a | |
| CVE-2026-4634 | Hig | 7.5 | >= 26.2.0, < 26.2.1 | 26.2.1 | Apr 2, 2026 | A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged process | |
| CVE-2026-4325 | Med | 5.3 | >= 26.2.0, < 26.2.1 | 26.2.1 | Apr 2, 2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password re | |
| CVE-2026-4282 | Hig | 7.4 | >= 26.2.0, < 26.2.1 | 26.2.1 | Apr 2, 2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable ac | |
| CVE-2026-3872 | Hig | 7.3 | >= 26.2.0, < 26.2.1 | 26.2.1 | Apr 2, 2026 | A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting i | |
| CVE-2026-2575 | Med | 5.3 | >= 26.4.0, < 26.4.10 | 26.4.10 | Mar 18, 2026 | A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to | |
| CVE-2026-2603 | Hig | 8.1 | >= 26.2.0, < 26.2.14 | 26.2.14 | Mar 18, 2026 | A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the | |
| CVE-2026-2092 | Hig | 7.7 | >= 26.2.0, < 26.2.14 | 26.2.14 | Mar 18, 2026 | A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious |
- affected >= 26.4.0, < 26.4.13fixed 26.4.13
A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malic
- affected >= 26.4.0, < 26.4.13fixed 26.4.13
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem p
- affected >= 26.6.0, < 26.6.5fixed 26.6.5
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a deleg
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitat
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) wher
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server w
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authentica
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for a
- affected >= 26.4.0, < 26.4.12fixed 26.4.12
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims
- affected < 26.4.12fixed 26.4.12
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable informati
- affected >= 26.2.0, < 26.2.1fixed 26.2.1
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an a
- affected >= 26.2.0, < 26.2.1fixed 26.2.1
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged process
- affected >= 26.2.0, < 26.2.1fixed 26.2.1
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password re
- affected >= 26.2.0, < 26.2.1fixed 26.2.1
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable ac
- affected >= 26.2.0, < 26.2.1fixed 26.2.1
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting i
- affected >= 26.4.0, < 26.4.10fixed 26.4.10
A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to
- affected >= 26.2.0, < 26.2.14fixed 26.2.14
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the
- affected >= 26.2.0, < 26.2.14fixed 26.2.14
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious
Page 2 of 3