VYPR

Keycloak

by Keycloak

Source repositories

CVEs (144)

  • CVE-2026-9791MedMay 28, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata…

  • CVE-2026-37981MedMay 19, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for…

  • CVE-2026-8830MedMay 19, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's…

  • CVE-2025-10044MedSep 5, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft…

  • CVE-2021-3856MedAug 26, 2022
    risk 0.21cvss 4.3epss 0.01

    ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if…

  • CVE-2020-10734LowFeb 11, 2021
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.

  • CVE-2026-94218LowSep 21, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A…

  • CVE-2026-9689MedMay 27, 2026
    risk 0.20cvss 4.2epss 0.00

    A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web…

  • CVE-2026-6856lowApr 13, 2026
    risk 0.20cvss 3.1epss —

    keycloak: keycloak: acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration

  • CVE-2026-1035LowJan 21, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not…

  • CVE-2020-27826MedMay 28, 2021
    risk 0.20cvss 4.2epss 0.01

    A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

  • CVE-2020-10686MedMay 4, 2020
    risk 0.20cvss 4.1epss 0.01

    A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

  • CVE-2025-14083LowJan 21, 2026
    risk 0.18cvss 2.7epss 0.00

    A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.

  • CVE-2022-2256LowSep 1, 2022
    risk 0.18cvss 3.8epss 0.01

    A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.

  • CVE-2020-1717LowFeb 11, 2021
    risk 0.18cvss 2.7epss 0.01

    A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.

  • CVE-2025-12150LowFeb 27, 2026
    risk 0.13cvss 3.1epss 0.00

    A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is…

  • CVE-2026-3911LowMar 11, 2026
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This…

  • CVE-2025-14082LowDec 10, 2025
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.

  • CVE-2024-10492LowNov 25, 2024
    risk 0.11cvss 2.7epss 0.01

    A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example,…

  • CVE-2020-10770MedDec 15, 2020
    risk 0.09cvss 5.3epss 0.70

    A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

Page 7 of 8