Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.49% | — | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management… | |
| Analizada | Alta (7.3) | 0.78% | 💥 PoC | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malicious client with a specially crafted… | |
| Analizada | Media (4.9) | 0.78% | — | Redhat Build OF Keycloak | 25/6/2026 | 1/7/2026 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and… | |
| Analizada | Media (4.9) | 0.30% | — | Redhat Build OF Keycloak | 11/6/2026 | 11/8/2026 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited… | |
| Modificada | Media (5.3) | 0.72% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing… | |
| Modificada | Media (6.8) | 0.52% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful… | |
| Modificada | Media (4.9) | 0.90% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response… | |
| Modificada | Media (4.3) | 0.49% | — | Redhat Build OF Keycloak | 28/5/2026 | 20/8/2026 | A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection.… | |
| Modificada | Media (6.5) | 0.38% | — | Redhat Build OF Keycloak | 28/5/2026 | 15/9/2026 | A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them… | |
| Modificada | Alta (7.3) | 0.49% | — | Redhat Build OF Keycloak | 28/5/2026 | 15/7/2026 | A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the… | |
| Modificada | Media (5.3) | 0.57% | 💥 PoC | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker… | |
| Modificada | Alta (7.5) | 0.26% | — | Redhat Build OF Keycloak | 28/5/2026 | 20/8/2026 | A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of… | |
| Modificada | Media (6.5) | 0.46% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an… | |
| Modificada | Media (4.3) | 0.37% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after… | |
| Modificada | Alta (8.8) | 0.59% | — | Redhat Build OF Keycloak | 27/5/2026 | 26/6/2026 | A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This… | |
| Modificada | Media (4.2) | 0.43% | — | Redhat Build OF Keycloak | 27/5/2026 | 20/8/2026 | A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the… | |
| Modificada | Alta (8.1) | 0.39% | — | Redhat Build OF Keycloak | 20/5/2026 | 23/7/2026 | A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account. | |
| Analizada | Alta (7.1) | 0.42% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be… | |
| Modificada | Alta (8.1) | 0.50% | — | Redhat Build OF Keycloak | 19/5/2026 | 15/7/2026 | A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further attacks. This vulnerability… | |
| Analizada | Media (6.8) | 0.38% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could… | |
| Analizada | Media (6.8) | 0.57% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads… | |
| Analizada | Media (4.3) | 0.42% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted… | |
| Analizada | Media (6.5) | 0.41% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers,… | |
| Analizada | Media (4.9) | 0.46% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized… | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Build OF Keycloak | 19/5/2026 | 6/10/2026 | A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session… |