Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.30% | — | Redhat Build OF Keycloak | 11/6/2026 | 11/8/2026 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited… | |
| Pendiente de análisis | Baja (2.7) | 0.45% | — | KeycloakAI | 5/6/2026 | 23/7/2026 | A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information… | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | HCL Hive Telco ObservabilityAIKeycloakAI | 4/6/2026 | 22/7/2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. | |
| Aplazada | Alta (8.8) | 0.65% | — | Cloakbrowser CloakserveAI | 1/6/2026 | 22/7/2026 | CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve port can supply a… | |
| Modificada | Media (5.3) | 0.72% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing… | |
| Modificada | Media (6.8) | 0.52% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful… | |
| Modificada | Media (4.9) | 0.90% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response… | |
| Modificada | Media (4.3) | 0.49% | — | Redhat Build OF Keycloak | 28/5/2026 | 20/8/2026 | A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection.… | |
| Modificada | Media (6.5) | 0.38% | — | Redhat Build OF Keycloak | 28/5/2026 | 15/9/2026 | A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them… | |
| Modificada | Alta (7.3) | 0.49% | — | Redhat Build OF Keycloak | 28/5/2026 | 15/7/2026 | A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the… | |
| Modificada | Media (5.3) | 0.57% | 💥 PoC | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker… | |
| Modificada | Alta (7.5) | 0.26% | — | Redhat Build OF Keycloak | 28/5/2026 | 20/8/2026 | A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of… | |
| Modificada | Media (6.5) | 0.46% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an… | |
| Modificada | Media (4.3) | 0.37% | — | Redhat Build OF Keycloak | 28/5/2026 | 26/6/2026 | A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after… | |
| Modificada | Alta (8.8) | 0.59% | — | Redhat Build OF Keycloak | 27/5/2026 | 26/6/2026 | A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This… | |
| Modificada | Media (4.2) | 0.43% | — | Redhat Build OF Keycloak | 27/5/2026 | 20/8/2026 | A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the… | |
| Modificada | Alta (8.1) | 0.39% | — | Redhat Build OF Keycloak | 20/5/2026 | 23/7/2026 | A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account. | |
| Analizada | Alta (7.1) | 0.42% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token that should not be… | |
| Modificada | Alta (8.1) | 0.50% | — | Redhat Build OF Keycloak | 19/5/2026 | 15/7/2026 | A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further attacks. This vulnerability… | |
| Analizada | Media (6.8) | 0.38% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could… | |
| Analizada | Media (6.8) | 0.57% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads… | |
| Analizada | Media (4.3) | 0.42% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted… | |
| Analizada | Media (6.5) | 0.41% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers,… | |
| Analizada | Media (4.9) | 0.46% | — | Redhat Build OF Keycloak | 19/5/2026 | 17/6/2026 | A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable information (PII) leakage, enabling unauthorized… | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Build OF Keycloak | 19/5/2026 | 6/10/2026 | A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session… |