Improper isolation or compartmentalization in Keycloak - CVE-2026-4282
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper isolation or compartmentalization in the SingleUseObjectProvider global key-value store when handling authorization codes. A remote attacker can forge authorization codes to escalate privileges.
Successful exploitation can result in the creation of admin-capable access tokens.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-4282
Red Hat build of Keycloak - addressed in versions 26.2.15, 26.4.11