Configuration in Keycloak - CVE-2025-11538

 

Configuration in Keycloak - CVE-2025-11538

Published: November 18, 2025 / Updated: December 1, 2025


Vulnerability identifier: #VU118581
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11538
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The issue may allow a remote attacker to gain unauthorized access to the application.

The issue exists due to insecure default configuration of the server with enabled debug mode. The server binds by default the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0), exposing the interface to remote attackers. 


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2025-11538

Install updates from vendor's website.

Keycloak - update to 26.4.4
Red Hat build of Keycloak - update to 26.4.4

External References

Related Security Bulletins