Redhat
Redhat Build OF Keycloak: vulnerabilidades y CVE
Redhat Build OF Keycloak tiene 113 vulnerabilidades publicadas, 102 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE113
Últimos 12 meses102
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19729 | Media (4.9) | 0.48% | — | 9 sept 2026 | A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete,… |
| CVE-2026-18963 | Crítica (9.1) | 3.2% | — | 18 ago 2026 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker… |
| CVE-2026-18967 | Alta (8.1) | 0.23% | — | 6 ago 2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in… |
| CVE-2026-16442 | Crítica (9.8) | 0.31% | — | 5 ago 2026 | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a… |
| CVE-2026-15572 | Alta (8.8) | 0.65% | — | 5 ago 2026 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate… |
| CVE-2026-16102 | Alta (8.1) | 0.46% | — | 5 ago 2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers,… |
| CVE-2026-16100 | Media (6.5) | 0.55% | — | 5 ago 2026 | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages… |
| CVE-2026-16071 | Media (5.4) | 0.32% | — | 5 ago 2026 | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP… |
| CVE-2026-15573 | Alta (8.1) | 0.46% | — | 5 ago 2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra… |
| CVE-2026-16443 | Crítica (9.1) | 0.26% | — | 5 ago 2026 | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that… |
| CVE-2026-18569 | Baja (3.7) | 0.25% | — | 4 ago 2026 | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The… |
| CVE-2026-18573 | Media (6.5) | 0.48% | — | 2 ago 2026 | A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce… |
| CVE-2026-18572 | Media (6.5) | 0.39% | — | 2 ago 2026 | Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can… |
| CVE-2026-18571 | Alta (7.2) | 0.55% | — | 2 ago 2026 | A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any… |
| CVE-2026-18570 | Media (5.4) | 0.30% | — | 2 ago 2026 | A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in… |
| CVE-2026-18218 | Media (5.4) | 0.29% | — | 31 jul 2026 | A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation… |
| CVE-2026-18217 | Media (4.7) | 0.33% | — | 31 jul 2026 | A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect… |
| CVE-2026-18215 | Alta (8.1) | 0.40% | — | 31 jul 2026 | Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange… |
| CVE-2026-18214 | Alta (8.1) | 0.40% | — | 31 jul 2026 | Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google… |
| CVE-2026-18211 | Media (5.4) | 0.31% | — | 31 jul 2026 | A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted… |
| CVE-2026-18209 | Media (4.7) | 0.41% | — | 31 jul 2026 | A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only… |
| CVE-2026-18208 | Media (6.5) | 0.34% | — | 31 jul 2026 | A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue… |
| CVE-2026-18206 | Baja (3.7) | 0.32% | — | 31 jul 2026 | A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to… |
| CVE-2026-18203 | Media (6.5) | 0.31% | — | 31 jul 2026 | A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple… |
| CVE-2026-16105 | Media (4.9) | 0.42% | — | 31 jul 2026 | A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite… |
| CVE-2026-18207 | Media (6.5) | 0.31% | — | 29 jul 2026 | A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges… |
| CVE-2026-18201 | Media (5.5) | 0.38% | — | 29 jul 2026 | Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider… |
| CVE-2026-17059 | Media (6.5) | 0.41% | — | 24 jul 2026 | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an… |
| CVE-2026-17048 | Media (4.9) | 0.42% | — | 24 jul 2026 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due… |
| CVE-2026-16108 | Media (6.5) | 0.37% | — | 17 jul 2026 | A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230