Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.89% | — | Redhat Build OF KeycloakRedhat Keycloak | 5/3/2026 | 15/7/2026 | A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain… | |
| Modificada | Alta (8.1) | 0.49% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/3/2026 | 14/9/2026 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative… | |
| Analizada | Baja (3.1) | 0.21% | — | Redhat Build OF KeycloakRedhat Keycloak | 27/2/2026 | 10/8/2026 | A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation.… | |
| Analizada | Media (4.9) | 0.32% | — | Redhat Build OF KeycloakRedhat Keycloak | 27/2/2026 | 17/6/2026 | A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Soflyy WP Wizard CloakAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soflyy WP Wizard Cloak wp-wizard-cloak allows Reflected XSS.This issue affects WP Wizard Cloak: from n/a through <= 1.0.1. | |
| Aplazada | Baja (3.8) | 0.43% | — | KeycloakAIDockerAI | 19/2/2026 | 17/6/2026 | A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously valid credentials can… | |
| Aplazada | Media (5) | 0.15% | — | KeycloakAI | 10/2/2026 | 17/6/2026 | A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials… | |
| Aplazada | Alta (8.1) | 0.49% | 💥 PoC | KeycloakAI | 9/2/2026 | 15/7/2026 | A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized… | |
| Aplazada | Alta (8.8) | 0.50% | — | KeycloakAI | 9/2/2026 | 15/7/2026 | A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for… | |
| Aplazada | Media (5.4) | 0.32% | — | KeycloakAI | 9/2/2026 | 17/6/2026 | A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA policy associated with multiple resources, the authorization check only verifies the caller's ownership against the first resource in the… | |
| Rechazada | Sin puntuar | — | — | KeycloakAIRedhat KeycloakAI | 2/2/2026 | 24/7/2026 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and… | |
| Aplazada | Baja (2.7) | 0.41% | — | KeycloakAI | 2/2/2026 | 17/6/2026 | A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings. | |
| Aplazada | Baja (3.1) | 0.42% | — | KeycloakAI | 26/1/2026 | 17/6/2026 | A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML responses,… | |
| Aplazada | Baja (2.7) | 0.36% | — | KeycloakAI | 21/1/2026 | 17/6/2026 | A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control. | |
| Aplazada | Media (6.5) | 0.49% | — | Keycloak-servicesAI | 21/1/2026 | 17/6/2026 | A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privileged client invokes… | |
| Aplazada | Baja (3.1) | 0.31% | — | KeycloakAI | 21/1/2026 | 17/6/2026 | A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent… | |
| Aplazada | Media (5.8) | 0.41% | — | KeycloakAI | 20/1/2026 | 17/6/2026 | A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the Keycloak server into… | |
| Aplazada | Baja (3.7) | 0.40% | — | KeycloakAI | 15/1/2026 | 9/8/2026 | A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing… | |
| Aplazada | Media (5.3) | 0.40% | — | KeycloakAI | 8/1/2026 | 17/6/2026 | A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of the "Bearer" authentication scheme. It accepts non-standard characters (such as tabs) as separators and tolerates case variations that deviate from RFC 6750 specifications. | |
| Aplazada | Alta (7.5) | 0.71% | — | KeycloakAI | 23/12/2025 | 17/6/2026 | A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiating TLS 1.2 client-initiated renegotiation requests to exhaust server CPU resources, making the service unavailable. | |
| Aplazada | Media (6) | 0.34% | — | KeycloakAI | 16/12/2025 | 7/10/2026 | A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorization resource management, specifically in ResourceSetService and PermissionTicketService. The system checks authorization against the resourceServer (client) ID provided in the API request, but… | |
| Aplazada | Baja (2.7) | 0.35% | — | KeycloakAI | 10/12/2025 | 17/6/2026 | A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint. | |
| Aplazada | Media (5.5) | 0.44% | — | KeycloakAI | 25/11/2025 | 17/6/2026 | A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration. | |
| Aplazada | Media (6.8) | 0.40% | — | KeycloakAI | 13/11/2025 | 17/6/2026 | A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a… | |
| Aplazada | Media (6) | 0.14% | — | KeycloakAI | 28/10/2025 | 17/6/2026 | A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user… |