SB20260806121 - Multiple vulnerabilities in Keycloak
Published: August 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2026-16102)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to forge administrative roles in their access token.
The vulnerability exists due to improper input validation in the default Dynamic Client Registration policy when processing User Property mappers with claim paths targeting sensitive internal claim locations. A remote user can use a limited Initial Access Token and write values to sensitive internal claim locations to forge administrative roles in their access token.
This can lead to takeover of other clients, theft of confidential secrets, and potential full administrative control over the realm.
2) Input validation error (CVE-ID: CVE-2026-16071)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and import unauthorized users into local storage.
The vulnerability exists due to improper input validation in the LDAP storage provider user search functionality when processing a specific LDAP entry distinguished name. A remote user can perform a search using a crafted LDAP entry DN to disclose sensitive information and import unauthorized users into local storage.
The issue occurs when a delegated administrator performs the search, allowing lookups outside the configured search boundary.
3) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-16443)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to a user account.
The vulnerability exists due to improper verification of cryptographic signature in the SAML metadata import functionality of the keycloak-services component when importing identity provider metadata that lacks specific usage attributes for keys. A remote attacker can forge a SAML response to gain unauthorized access to a user account.
Exploitation requires knowledge of the target user\'s external identifier.
4) Origin validation error (CVE-ID: CVE-2026-16442)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and modify data.
The vulnerability exists due to origin validation error in the SAML IdP-initiated broker login flow when processing IdP-initiated broker login requests. A remote attacker can send a specially crafted SAML IdP-initiated broker login request to disclose sensitive information and modify data.
5) Resource exhaustion (CVE-ID: CVE-2026-16100)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in user-event metrics recording when processing failed account operations with request-controlled error text. A remote user can submit crafted requests with unique input values to cause a denial of service.
Only instances with metrics enabled are vulnerable.
6) Type Confusion (CVE-ID: CVE-2026-15572)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain full administrative access to the Keycloak realm.
The vulnerability exists due to access of resource using incompatible type in the Dynamic Client Registration \"Allowed Protocol Mapper Types\" policy when processing client update requests. A remote user can register an allowed mapper type with a malicious configuration and then swap it to a restricted high-privilege mapper type to gain full administrative access to the Keycloak realm.
Exploitation requires client registration privileges.
7) Improper Authorization (CVE-ID: CVE-2026-15573)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authorization and access restricted areas.
The vulnerability exists due to improper access control in the PathMatcher component when handling request paths containing unnormalized URIs. A remote user can send a specially crafted request with a trailing slash or matrix parameters to bypass authorization and access restricted areas.
The issue can cause less restrictive security policies to be applied than intended, including exposure of administrative areas.
Remediation
Install update from vendor's website.
References
- https://github.com/keycloak/keycloak/security/advisories/GHSA-95cx-vmr5-3cmr
- https://github.com/keycloak/keycloak/security/advisories/GHSA-hmr6-pxx9-552p
- https://github.com/keycloak/keycloak/security/advisories/GHSA-f8m4-v488-rmrm
- https://github.com/keycloak/keycloak/security/advisories/GHSA-fgq2-hxm5-8xg2
- https://github.com/keycloak/keycloak/security/advisories/GHSA-3692-rrj9-24qw
- https://github.com/keycloak/keycloak/security/advisories/GHSA-95rm-h7g9-rhcf
- https://github.com/keycloak/keycloak/security/advisories/GHSA-2888-g6qc-w4mj