Keycloak是Keycloak组织开源的一种开源身份和访问管理解决方案。 Keycloak存在权限许可和访问控制问题漏洞,该漏洞源于Identity Provider (IdP) mapper组件问题,可能导致具有有限权限的管理员通过创建“Hardcoded Role”mapper分配高级管理角色,绕过安全检查并获得对完整领域的完全控制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14164 | 7.5 HIGH | Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_bu |
| CVE-2026-4629 | 6.5 MEDIUM | Keycloak: keycloak: privilege escalation through hardcoded role mapper injection |
| CVE-2026-12610 | 6.4 MEDIUM | Sssd: use-after-free crash in sssd' 'sssd_pam' process |
| CVE-2026-13316 | 4.4 MEDIUM | Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman c |
| CVE-2026-14209 | 4.3 MEDIUM | Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses |
No comments yet