SB2026091071 - Multiple vulnerabilities in Keycloak



SB2026091071 - Multiple vulnerabilities in Keycloak

Published: September 10, 2026

Security Bulletin ID SB2026091071
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-4366)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper handling of HTTP redirects in Keycloak client configuration request processing when processing certain client configuration requests. A remote attacker can cause the server to make unintended requests to internal or restricted resources to disclose sensitive information.

Cloud metadata endpoints may be accessible, and the issue may enable internal network infrastructure mapping.


2) Information Exposure Through an Error Message (CVE-ID: CVE-2026-4633)

CWE-ID: CWE-209 - Information Exposure Through an Error Message

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose user information.

The vulnerability exists due to generation of error messages containing sensitive information in Keycloak\'s identity-first login flow when Organizations are enabled. A remote attacker can exploit differential error messages to disclose user information.

Exploitation enables user enumeration.


Remediation

Install update from vendor's website.