VYPR

Bitnami package

keycloak

pkg:bitnami/keycloak

Vulnerabilities (52)

  • CVE-2026-2366LowMar 12, 2026
    affected >= 26.4.0, < 26.4.11fixed 26.4.11

    A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker

  • CVE-2026-3429MedMar 11, 2026
    affected >= 26.4.0, < 26.4.11fixed 26.4.11

    A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the vic

  • CVE-2026-3911LowMar 11, 2026
    affected >= 26.4.0, < 26.4.1fixed 26.4.1

    A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This u

  • CVE-2026-3047HigMar 5, 2026
    affected >= 26.2.0, < 26.2.1fixed 26.2.1

    A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This a

  • CVE-2026-3009HigMar 5, 2026
    affected >= 26.4.0, < 26.4.1fixed 26.4.1

    A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request

  • CVE-2025-12150LowFeb 27, 2026
    affected < 26.4.4fixed 26.4.4

    A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is confi

  • CVE-2026-0871MedFeb 27, 2026
    affected < 26.4.9fixed 26.4.9

    A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles,

  • CVE-2025-3910MedApr 29, 2025
    affected >= 26.0.0, < 26.0.11fixed 26.0.11

    A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

  • CVE-2024-7341HigSep 9, 2024
    affected >= 22.0.0, < 22.0.12fixed 22.0.12

    A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session be

  • CVE-2024-7318MedSep 9, 2024
    affected >= 22.0.0, < 24.0.7fixed 24.0.7

    A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute

  • CVE-2024-7260MedSep 9, 2024
    affected < 24.0.7fixed 24.0.7

    An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is safe,

  • CVE-2024-4629MedSep 3, 2024
    affected >= 22.0.0, < 22.12.0fixed 22.12.0

    A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system lo

Page 3 of 3