org.keycloak
174 tracked vulnerabilities.
CVE-2026-7500
MEDIUM
Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
Apr 30, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-37980
MEDIUM
Org.keycloak.forms.login: keycloak: keycloak: arbitrary code execution via stored cross-site scripting (xss) in organization selection login page
Apr 14, 2026
CVSS 6.9
EPSS 0.00
CVE-2026-37977
LOW
Keycloak: org.keycloak.protocol.oidc.grants.ciba: keycloak: information disclosure via cors header injection due to unvalidated jwt azp claim
Apr 06, 2026
CVSS 3.7
EPSS 0.00
CVE-2026-4636
HIGH
Keycloak UMA Policy - Unauthorized Resource Access
Apr 02, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-4634
HIGH
Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
Apr 02, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-4325
MEDIUM
Keycloak: keycloak: replay of action tokens via improper handling of single-use entries
Apr 02, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-4282
HIGH
Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
Apr 02, 2026
CVSS 7.4
EPSS 0.00
CVE-2026-3872
HIGH
Red Hat Keycloak 26.2 and 26.4 - redirect_uri Access Token Disclosure
Apr 02, 2026
CVSS 7.3
EPSS 0.00
CVE-2026-3190
MEDIUM
Keycloak: keycloak: information disclosure via improper role enforcement in uma 2.0 protection api
Mar 26, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-3121
MEDIUM
Keycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-clients permission
Mar 26, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-4874
LOW
Org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side request forgery via oidc token endpoint manipulation
Mar 26, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-4633
LOW
Keycloak: keycloak: user enumeration via differential error messages
Mar 23, 2026
CVSS 3.7
EPSS 0.00
CVE-2026-4628
MEDIUM
Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control
Mar 23, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2575
MEDIUM
Keycloak: keycloak: denial of service due to excessive samlrequest decompression
Mar 18, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-2603
HIGH
Keycloak: keycloak: unauthorized authentication via disabled saml identity provider
Mar 18, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-2092
HIGH
Keycloak-services: keycloak: unauthorized access via improper validation of encrypted saml assertions
Mar 18, 2026
CVSS 7.7
EPSS 0.00
CVE-2026-2366
LOW
Red Hat build of Keycloak 26.4 - Authenticated Authorization Bypass in Admin API
Mar 12, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-3429
MEDIUM
Keycloak Account REST API - Privilege Escalation
Mar 11, 2026
CVSS 4.2
EPSS 0.00
CVE-2026-3911
LOW
Keycloak - Authenticated Unauthorized User Attribute Exposure via UserResource Endpoint
Mar 11, 2026
CVSS 2.7
EPSS 0.00
CVE-2026-3047
HIGH
Keycloak SAML Broker - Authentication Bypass via Disabled IdP-Initiated Client
Mar 05, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-3009
HIGH
Keycloak < 26.5.5 - Incorrect Authorization via Disabled Identity Provider Bypass
Mar 05, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-0871
MEDIUM
Keycloak < 26.5.2 - Incorrect Privilege Assignment via Unmanaged Attribute Bypass
Feb 27, 2026
CVSS 4.9
EPSS 0.00
CVE-2026-2733
LOW
Keycloak - Improper Authorization via Docker v2 Authentication Endpoint
Feb 19, 2026
CVSS 3.8
EPSS 0.00
CVE-2026-1529
HIGH
Keycloak 26.5.0-26.5.2 - Unauthenticated Organization Access via JWT Invitation Token Tampering
Feb 09, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-1486
HIGH
Keycloak 26.5.0-26.5.2 - Unauthenticated Token Issuance via Disabled Identity Provider Bypass
Feb 09, 2026
CVSS 8.8
EPSS 0.00
Products
keycloak-services 74
keycloak-core 48
keycloak-parent 25
keycloak-quarkus-server 9
keycloak-server-spi-private 5
keycloak-ldap-federation 4
keycloak-saml-core 4
keycloak-model-jpa 3
keycloak-saml-adapter-core 3
keycloak-model-infinispan 2
keycloak-quarkus-dist 2
keycloak-account-ui 1
keycloak-adapter-core 1
keycloak-admin-ui 1
keycloak-authz-client 1
keycloak-broker-saml 1
keycloak-common 1
keycloak-js-admin-client 1
keycloak-model-storage-services 1
keycloak-oidc-client-adapter-pom 1
Quick Filters