org.keycloak

174 tracked vulnerabilities.

CVE-2026-7500 MEDIUM
Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
Apr 30, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-37980 MEDIUM
Org.keycloak.forms.login: keycloak: keycloak: arbitrary code execution via stored cross-site scripting (xss) in organization selection login page
Apr 14, 2026
CVSS 6.9
EPSS 0.00
CVE-2026-37977 LOW
Keycloak: org.keycloak.protocol.oidc.grants.ciba: keycloak: information disclosure via cors header injection due to unvalidated jwt azp claim
Apr 06, 2026
CVSS 3.7
EPSS 0.00
CVE-2026-4636 HIGH
Keycloak UMA Policy - Unauthorized Resource Access
Apr 02, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-4634 HIGH
Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
Apr 02, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-4325 MEDIUM
Keycloak: keycloak: replay of action tokens via improper handling of single-use entries
Apr 02, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-4282 HIGH
Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
Apr 02, 2026
CVSS 7.4
EPSS 0.00
CVE-2026-3872 HIGH
Red Hat Keycloak 26.2 and 26.4 - redirect_uri Access Token Disclosure
Apr 02, 2026
CVSS 7.3
EPSS 0.00
CVE-2026-3190 MEDIUM
Keycloak: keycloak: information disclosure via improper role enforcement in uma 2.0 protection api
Mar 26, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-3121 MEDIUM
Keycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-clients permission
Mar 26, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-4874 LOW
Org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side request forgery via oidc token endpoint manipulation
Mar 26, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-4633 LOW
Keycloak: keycloak: user enumeration via differential error messages
Mar 23, 2026
CVSS 3.7
EPSS 0.00
CVE-2026-4628 MEDIUM
Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control
Mar 23, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2575 MEDIUM
Keycloak: keycloak: denial of service due to excessive samlrequest decompression
Mar 18, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-2603 HIGH
Keycloak: keycloak: unauthorized authentication via disabled saml identity provider
Mar 18, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-2092 HIGH
Keycloak-services: keycloak: unauthorized access via improper validation of encrypted saml assertions
Mar 18, 2026
CVSS 7.7
EPSS 0.00
CVE-2026-2366 LOW
Red Hat build of Keycloak 26.4 - Authenticated Authorization Bypass in Admin API
Mar 12, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-3429 MEDIUM
Keycloak Account REST API - Privilege Escalation
Mar 11, 2026
CVSS 4.2
EPSS 0.00
CVE-2026-3911 LOW
Keycloak - Authenticated Unauthorized User Attribute Exposure via UserResource Endpoint
Mar 11, 2026
CVSS 2.7
EPSS 0.00
CVE-2026-3047 HIGH
Keycloak SAML Broker - Authentication Bypass via Disabled IdP-Initiated Client
Mar 05, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-3009 HIGH
Keycloak < 26.5.5 - Incorrect Authorization via Disabled Identity Provider Bypass
Mar 05, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-0871 MEDIUM
Keycloak < 26.5.2 - Incorrect Privilege Assignment via Unmanaged Attribute Bypass
Feb 27, 2026
CVSS 4.9
EPSS 0.00
CVE-2026-2733 LOW
Keycloak - Improper Authorization via Docker v2 Authentication Endpoint
Feb 19, 2026
CVSS 3.8
EPSS 0.00
CVE-2026-1529 HIGH
Keycloak 26.5.0-26.5.2 - Unauthenticated Organization Access via JWT Invitation Token Tampering
Feb 09, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-1486 HIGH
Keycloak 26.5.0-26.5.2 - Unauthenticated Token Issuance via Disabled Identity Provider Bypass
Feb 09, 2026
CVSS 8.8
EPSS 0.00