Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.4) | — | — | KeycloakAI | 6/10/2026 | 6/10/2026 | A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client… | |
| Recibida | Media (6.5) | 0.22% | — | KeycloakAI | 5/10/2026 | 5/10/2026 | A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that… | |
| Recibida | Media (5.7) | 0.20% | — | KeycloakAI | 5/10/2026 | 5/10/2026 | A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a… | |
| Recibida | Media (4) | 0.12% | — | KeycloakAI | 5/10/2026 | 5/10/2026 | A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a… | |
| Pendiente de análisis | Media (6.5) | 0.21% | — | KeycloakAI | 1/10/2026 | 1/10/2026 | A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive… | |
| Pendiente de análisis | Baja (3.7) | 0.23% | — | KeycloakAI | 28/9/2026 | 28/9/2026 | A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider… | |
| Pendiente de análisis | Media (6.6) | 0.24% | — | KeycloakAI | 25/9/2026 | 26/9/2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what… | |
| Pendiente de análisis | Media (6.8) | 0.14% | — | KeycloakAI | 25/9/2026 | 25/9/2026 | Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard Token Exchange V2 feature does not check for this certificate. This allows an… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | KeycloakAI | 24/9/2026 | 24/9/2026 | A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed… | |
| Pendiente de análisis | Media (6.6) | 0.24% | — | KeycloakAI | 24/9/2026 | 24/9/2026 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting… | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | KeycloakAI | 24/9/2026 | 26/9/2026 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations… | |
| Pendiente de análisis | Media (4.2) | 0.18% | — | KeycloakAI | 23/9/2026 | 26/9/2026 | A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request… | |
| Pendiente de análisis | Media (6.8) | 0.24% | — | KeycloakAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow… | |
| Pendiente de análisis | Media (6.8) | 0.19% | — | KeycloakAI | 22/9/2026 | 22/9/2026 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Distribution Center (KDC) by requesting a server ticket. This allows an attacker on… | |
| Pendiente de análisis | Baja (3.1) | 0.31% | — | KeycloakAI | 21/9/2026 | 22/9/2026 | A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by… | |
| Pendiente de análisis | Baja (3.5) | 0.24% | — | KeycloakAI | 21/9/2026 | 24/9/2026 | A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system incorrectly merges the permissions from both resources when one user requests an… | |
| Pendiente de análisis | Media (5.5) | 0.30% | — | KeycloakAI | 21/9/2026 | 22/9/2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows… | |
| Pendiente de análisis | Media (4.9) | 0.39% | — | KeycloakAI | 21/9/2026 | 22/9/2026 | A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | KeycloakAI | 19/9/2026 | 22/9/2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows a delegated administrator, who should be restricted from resetting passwords, to… | |
| Pendiente de análisis | Media (6.6) | 0.40% | — | KeycloakAI | 19/9/2026 | 22/9/2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with… | |
| Pendiente de análisis | Media (4.2) | 0.23% | — | KeycloakAI | 19/9/2026 | 22/9/2026 | A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is still enabled before… | |
| Pendiente de análisis | Alta (7.4) | 0.40% | — | KeycloakAIMysqlAIMariadbAI | 17/9/2026 | 22/9/2026 | A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | Keycloak-servicesAI | 16/9/2026 | 16/9/2026 | A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in… | |
| Pendiente de análisis | Alta (7.2) | 0.45% | — | KeycloakAI | 16/9/2026 | 16/9/2026 | Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles. | |
| Pendiente de análisis | Alta (7.5) | 0.81% | — | Keycloak ServicesAI | 16/9/2026 | 16/9/2026 | A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tags from unauthenticated requests and stores them in a permanent… |