Input validation error in Keycloak - CVE-2026-16071

 

Input validation error in Keycloak - CVE-2026-16071

Published: August 6, 2026


Vulnerability identifier: #VU141169
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16071
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and import unauthorized users into local storage.

The vulnerability exists due to improper input validation in the LDAP storage provider user search functionality when processing a specific LDAP entry distinguished name. A remote user can perform a search using a crafted LDAP entry DN to disclose sensitive information and import unauthorized users into local storage.

The issue occurs when a delegated administrator performs the search, allowing lookups outside the configured search boundary.


Affected software

Keycloak

How to mitigate CVE-2026-16071

Install security update from vendor's website.

Keycloak - addressed in versions 26.4.14, 26.6.5, 26.7.1

External References

Related Security Bulletins