Keycloak是Keycloak组织开源的一种开源身份和访问管理解决方案。 Keycloak存在授权问题漏洞,该漏洞源于使用“brute-force-user”端点时,缺少对管理员是否拥有特定用户“view”权限的检查,可能导致绕过安全限制的管理员访问用户的完整配置文件,包括敏感信息和安全元数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.14-1< * |
unaffected |
26.4-22< * |
unaffected | ||
26.4-22< * |
unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.4.14 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.5-1< * |
unaffected |
26.6-11< * |
unaffected | ||
26.6-11< * |
unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.6.5 | any |
unaffected |
any |
unaffected | ||
any |
unaffected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.14-1 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-22 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-22 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.14 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.14 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.5-1 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-11 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-11 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.5 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.5 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.5 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14164 | 7.5 HIGH | Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_bu |
| CVE-2026-12388 | 6.5 MEDIUM | Keycloak-broker: keycloak: privilege escalation to realm administrator via improper author |
| CVE-2026-4629 | 6.5 MEDIUM | Keycloak: keycloak: privilege escalation through hardcoded role mapper injection |
| CVE-2026-12610 | 6.4 MEDIUM | Sssd: use-after-free crash in sssd' 'sssd_pam' process |
| CVE-2026-13316 | 4.4 MEDIUM | Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman c |
No comments yet