SB2026091062 - Multiple vulnerabilities in Keycloak
Published: September 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2025-14083)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose backend schema and rules.
The vulnerability exists due to improper access control in the Keycloak Admin REST API when handling administrative API requests. A remote privileged user can access backend schema and rules to disclose backend schema and rules.
2) Improper access control (CVE-ID: CVE-2026-3429)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to take over an account.
The vulnerability exists due to improper access control in the Keycloak Account REST API when performing sensitive MFA credential actions from a lower-security session. A remote user can delete a victim\'s registered MFA/OTP credential and register an attacker-controlled MFA device to take over an account.
Exploitation requires possession of the victim\'s password.
3) Excessive Platform Resource Consumption within a Loop (CVE-ID: CVE-2026-4634)
CWE-ID: CWE-1050 - Excessive Platform Resource Consumption within a Loop
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive platform resource consumption within a loop in the OpenID Connect token endpoint when processing a specially crafted POST request with an excessively long scope parameter. A remote attacker can send a specially crafted POST request with an excessively long scope parameter to cause a denial of service.
4) Incorrect Behavior Order: Authorization Before Parsing and Canonicalization (CVE-ID: CVE-2026-4636)
CWE-ID: CWE-551 - Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain unauthorized permissions to victim-owned resources.
The vulnerability exists due to authorization before parsing and canonicalization in Keycloak User-Managed Access policy validation when creating a policy with resource identifiers owned by other users. A remote user can include victim-owned resource identifiers in a policy creation request for an attacker-owned resource to gain unauthorized permissions to victim-owned resources.
The user must have the uma_protection role. Successful exploitation can enable acquisition of a Requesting Party Token.
5) Open redirect (CVE-ID: CVE-2026-3872)
CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper redirect URI validation in the OIDC authorization endpoint when processing redirect URIs containing a ..;/ path traversal sequence and using a wildcard allowed path. A remote user can control another path on the same web server and bypass the allowed redirect URI path to disclose sensitive information.
User interaction is required.
6) Improper isolation or compartmentalization (CVE-ID: CVE-2026-4282)
CWE-ID: CWE-653 - Improper isolation or compartmentalization
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper isolation or compartmentalization in the SingleUseObjectProvider global key-value store when handling authorization codes. A remote attacker can forge authorization codes to escalate privileges.
Successful exploitation can result in the creation of admin-capable access tokens.
Remediation
Install update from vendor's website.
References
- https://github.com/advisories/GHSA-594w-2fwp-jwrc
- https://github.com/keycloak/keycloak/releases/tag/26.5.7
- https://github.com/keycloak/keycloak/issues/45493
- https://github.com/advisories/GHSA-8g9r-9wjw-37j4
- https://github.com/keycloak/keycloak/commit/68f5779230d08825e6a4b4e23471fade16434178
- https://github.com/advisories/GHSA-h4wv-g838-66g3
- https://github.com/keycloak/keycloak/commit/b455ee4f28abb6f2120aff72fd179589cc5267a0
- https://github.com/advisories/GHSA-f2hx-5fx3-hmcv
- https://github.com/keycloak/keycloak/commit/995832f8b74b02833d106c8788bb7a78634aa725
- https://github.com/advisories/GHSA-cjm2-j6cm-6p6m
- https://github.com/keycloak/keycloak/commit/35a71b00bc856ac402711130f60190d3a24795e7
- https://github.com/advisories/GHSA-hj93-h7pg-fh6v
- https://github.com/keycloak/keycloak/commit/9046f201125a6fd6be9c116b99d348509d99d4a5