Server-Side Request Forgery (SSRF) in Keycloak - CVE-2026-4366

 

Server-Side Request Forgery (SSRF) in Keycloak - CVE-2026-4366

Published: September 10, 2026


Vulnerability identifier: #VU148942
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2026-4366
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper handling of HTTP redirects in Keycloak client configuration request processing when processing certain client configuration requests. A remote attacker can cause the server to make unintended requests to internal or restricted resources to disclose sensitive information.

Cloud metadata endpoints may be accessible, and the issue may enable internal network infrastructure mapping.


Affected software

Keycloak

How to mitigate CVE-2026-4366

Install security update from vendor's website.

Keycloak - update to 26.6.1

External References

Related Security Bulletins