SB2026091060 - Multiple vulnerabilities in Red Hat build of Keycloak 26.2



SB2026091060 - Multiple vulnerabilities in Red Hat build of Keycloak 26.2

Published: September 10, 2026

Security Bulletin ID SB2026091060
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-1529)

CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to gain unauthorized access to an organization.

The vulnerability exists due to improper verification of cryptographic signatures in Keycloak invitation token validation when processing a modified invitation token JSON Web Token payload. A remote user can modify the organization ID and target email in a legitimate invitation token to gain unauthorized access to an organization.


2) Incorrect Privilege Assignment (CVE-ID: CVE-2025-14778)

CWE-ID: CWE-266 - Incorrect Privilege Assignment

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper authorization in the UserManagedPermissionService (UMA Protection API) when updating or deleting UMA policies associated with multiple resources. A remote user can update a shared policy to modify authorization rules for resources owned by another user to escalate privileges.

Exploitation requires ownership of the first resource in the policy\'s resource list.


Remediation

Install update from vendor's website.