Input validation error in Keycloak - CVE-2026-16071
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and import unauthorized users into local storage.
The vulnerability exists due to improper input validation in the LDAP storage provider user search functionality when processing a specific LDAP entry distinguished name. A remote user can perform a search using a crafted LDAP entry DN to disclose sensitive information and import unauthorized users into local storage.
The issue occurs when a delegated administrator performs the search, allowing lookups outside the configured search boundary.