Keycloak 是一款开源的身份与访问管理解决方案。研究人员发现了一个漏洞:拥有“模拟(impersonation)”角色的用户可以模拟(impersonate)领域(realm)管理员。这使得攻击者能够获取对领域(realm)的完全管理权限,包括管理用户、客户端和角色的能力。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-26 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-26 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.16-2 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.16 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.16 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-20 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.7-3 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-20 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.7 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.7 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.7 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat Data Grid 8 | - |
cpe:/a:redhat:jboss_data_grid:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74909 | 8.1 HIGH | Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo |
| CVE-2026-79651 | 7.5 HIGH | Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching |
| CVE-2026-18212 | 7.5 HIGH | Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state |
| CVE-2026-42784 | 7.4 HIGH | Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio |
| CVE-2026-92615 | 6.6 MEDIUM | Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena |
| CVE-2026-92358 | 6.4 MEDIUM | Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil |
| CVE-2026-92091 | 5.9 MEDIUM | Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops |
| CVE-2026-19607 | 5.3 MEDIUM | Keycloak-services: keycloak-services: broker-originated username collision causes account |
No comments yet