Open redirect in Keycloak - CVE-2026-3872

 

Open redirect in Keycloak - CVE-2026-3872

Published: September 10, 2026


Vulnerability identifier: #VU148938
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3872
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper redirect URI validation in the OIDC authorization endpoint when processing redirect URIs containing a ..;/ path traversal sequence and using a wildcard allowed path. A remote user can control another path on the same web server and bypass the allowed redirect URI path to disclose sensitive information.

User interaction is required.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-3872

Install security update from vendor's website.

Keycloak - update to 26.5.7
Red Hat build of Keycloak - addressed in versions 26.2.15, 26.4.11

External References

Related Security Bulletins