Authorization bypass through user-controlled key in Keycloak - CVE-2026-4630
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose information and modify or delete data.
The vulnerability exists due to authorization bypass through a user-controlled key in the Authorization Services Protection API endpoint when handling requests that specify the UUID of a resource owned by another Resource Server in the same realm. A remote user can send GET, PUT, or DELETE requests using a known or obtained resource UUID to disclose information and modify or delete data.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-4630
Red Hat build of Keycloak - update to 26.4.12