Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
321 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Modificada | Media (5.9) | 0.29% | — | Redhat Build OF Keycloak | 17/7/2026 | 16/9/2026 | A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially… | |
| Modificada | Media (4.9) | 0.43% | — | Redhat Build OF Keycloak | 17/7/2026 | 16/9/2026 | A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link,… | |
| Analizada | Media (5.5) | 0.34% | — | Redhat Build OF Keycloak | 17/7/2026 | 9/8/2026 | A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Analizada | Alta (8.1) | 0.56% | — | Redhat Build OF Keycloak | 16/7/2026 | 9/8/2026 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control… | |
| Analizada | Media (4.8) | 0.28% | — | Redhat Build OF Keycloak | 5/7/2026 | 11/8/2026 | A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves the email address from the userinfo response but retrieves the… | |
| Analizada | Baja (2.7) | 0.38% | — | Redhat Build OF Keycloak | 3/7/2026 | 11/8/2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to… | |
| Analizada | Media (5.4) | 0.32% | — | Redhat Build OF Keycloak | 3/7/2026 | 11/8/2026 | A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see… | |
| Modificada | Media (4.9) | 0.38% | — | Redhat Build OF Keycloak | 3/7/2026 | 31/8/2026 | A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of… | |
| Modificada | Media (6.5) | 0.49% | — | Redhat Build OF Keycloak | 30/6/2026 | 5/8/2026 | A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege… | |
| Modificada | Media (4.3) | 0.39% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 30/6/2026 | 5/8/2026 | A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific… | |
| Analizada | Media (6.5) | 0.40% | — | Redhat Build OF Keycloak | 30/6/2026 | 1/7/2026 | A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns… | |
| Analizada | Alta (8.1) | 0.30% | — | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any… | |
| Modificada | Alta (8.1) | 0.65% | — | Redhat Build OF Keycloak | 25/6/2026 | 14/9/2026 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query… | |
| Analizada | Media (4.6) | 0.29% | — | Redhat Build OF Keycloak | 25/6/2026 | 1/7/2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of… | |
| Analizada | Media (6.5) | 0.46% | — | Redhat Build OF Keycloak | 25/6/2026 | 1/7/2026 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the… | |
| Analizada | Alta (7.7) | 0.49% | — | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management… | |
| Analizada | Alta (7.3) | 0.78% | 💥 PoC | Redhat Build OF Keycloak | 25/6/2026 | 15/7/2026 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malicious client with a specially crafted… | |
| Analizada | Media (4.9) | 0.78% | — | Redhat Build OF Keycloak | 25/6/2026 | 1/7/2026 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and… | |
| Analizada | Media (4.9) | 0.30% | — | Redhat Build OF Keycloak | 11/6/2026 | 11/8/2026 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited… | |
| Pendiente de análisis | Baja (2.7) | 0.45% | — | KeycloakAI | 5/6/2026 | 23/7/2026 | A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information… | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | HCL Hive Telco ObservabilityAIKeycloakAI | 4/6/2026 | 22/7/2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. | |
| Modificada | Media (5.3) | 0.72% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing… | |
| Modificada | Media (6.8) | 0.52% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful… |