SB2026091076 - Multiple vulnerabilities in Keycloak
Published: September 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-45292)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
2) Insufficient Granularity of Access Control (CVE-ID: CVE-2026-14613)
CWE-ID: CWE-1220 - Insufficient Granularity of Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive group information.
The vulnerability exists due to insufficient granularity of access control in Keycloak\'s administrative interface when viewing groups assigned to a role. A remote user can view groups assigned to a role they are permitted to view to disclose sensitive group information.
Only instances with Fine-Grained Admin Permissions version 2 enabled are affected.
CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to modify dynamically determined object attributes.
The vulnerability exists due to improper control of dynamically determined object attributes in jackson-databind record deserialization when applying a PropertyNamingStrategy to `@JsonIgnore`-annotated Record properties. A remote attacker can supply a specially crafted JSON key to modify dynamically determined object attributes.
This issue affects Java Records during deserialization when a naming strategy is used and `@JsonIgnore` is relied on to prevent a component from being set from input.
4) Incorrect authorization (CVE-ID: CVE-2026-59889)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in UnwrappedPropertyHandler.processUnwrapped() when deserializing @JsonUnwrapped container properties under a less-privileged active view. A remote user can supply crafted JSON values for a property annotated with both @JsonView and @JsonUnwrapped to escalate privileges.
This affects the write-side authorization behavior of @JsonView during deserialization, including merge and builder-based deserialization paths.
5) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-15945)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive group attributes and configuration.
The vulnerability exists due to authorization bypass through a user-controlled key in the group search functionality of the Keycloak server administrative API when searching for a child group the user is authorized to view. A remote user can search for an authorized child group to view full details of an unauthorized parent group and disclose sensitive group attributes and configuration.
Fine-Grained Admin Permissions v2 must be enabled.
6) Information disclosure (CVE-ID: CVE-2026-17048)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive credentials.
The vulnerability exists due to improper boundary enforcement in the Keycloak Admin REST API when processing requests for rotated client secrets stored in a secure vault. A remote privileged user can retrieve resolved secrets instead of vault placeholders to disclose sensitive credentials.
Exploitation requires delegated administrator permissions that are limited to viewing resources.
7) Predictable from Observable State (CVE-ID: CVE-2026-15571)
CWE-ID: CWE-341 - Predictable from Observable State
CVSSv4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to take over a victim\'s account.
The vulnerability exists due to predictable hash generation in the legacy client-initiated account-linking endpoint when processing account-linking requests. A remote user can trick a user into authenticating and forge a valid linking URL to connect the victim\'s account to an attacker-controlled external identity to take over a victim\'s account.
User interaction is required to authenticate.
8) Weak Password Recovery Mechanism for Forgotten Password (CVE-ID: CVE-2026-18963)
CWE-ID: CWE-640 - Weak password recovery mechanism
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to take over arbitrary user accounts.
The vulnerability exists due to a weak password recovery mechanism in the reset-credentials flow of the keycloak-services component when handling password reset requests. A remote attacker can bypass the required email verification link and set new credentials to take over arbitrary user accounts.
Remediation
Install update from vendor's website.
References
- https://github.com/keycloak/keycloak/releases/tag/26.7.2
- https://github.com/advisories/GHSA-j2vp-w8g9-p6hf
- https://github.com/advisories/GHSA-hp9p-wj8m-c339
- https://github.com/advisories/GHSA-p3wj-5684-x596
- https://github.com/advisories/GHSA-m639-f4cw-m3hm
- https://github.com/advisories/GHSA-4gv3-mc9p-5wqc
- https://github.com/keycloak/keycloak/commit/dc2d4e524b4dae85aedc87ca28b9e4fa567d56c1