Improper isolation or compartmentalization in Red Hat build of Keycloak - CVE-2026-4325
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to accounts.
The vulnerability exists due to improper type and namespace isolation in the SingleUseObjectProvider when handling single-use entries. A remote attacker can delete arbitrary single-use entries to replay consumed action tokens.
User interaction is required.