SB2026091071 - Multiple vulnerabilities in Keycloak
Published: September 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-4366)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of HTTP redirects in Keycloak client configuration request processing when processing certain client configuration requests. A remote attacker can cause the server to make unintended requests to internal or restricted resources to disclose sensitive information.
Cloud metadata endpoints may be accessible, and the issue may enable internal network infrastructure mapping.
2) Information Exposure Through an Error Message (CVE-ID: CVE-2026-4633)
CWE-ID: CWE-209 - Information Exposure Through an Error Message
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose user information.
The vulnerability exists due to generation of error messages containing sensitive information in Keycloak\'s identity-first login flow when Organizations are enabled. A remote attacker can exploit differential error messages to disclose user information.
Exploitation enables user enumeration.
Remediation
Install update from vendor's website.