在 Keycloak 的 keycloak-services 组件的“首个经纪人登录”流程中发现了一个漏洞。该组件负责处理用户通过外部身份提供商登录时的初始身份验证和账户关联操作。此漏洞允许攻击者在外部身份提供商上注册一个与 Keycloak 中存在的用户名相匹配的名称,从而触发 Keycloak 中的用户名冲突,导致合法用户被锁定在其账户之外。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-26 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-26 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.16-2 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.16 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.16 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-20 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.7-3 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-20 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.7 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.7 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74909 | 8.1 HIGH | Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo |
| CVE-2026-79651 | 7.5 HIGH | Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching |
| CVE-2026-18212 | 7.5 HIGH | Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state |
| CVE-2026-42784 | 7.4 HIGH | Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio |
| CVE-2026-17526 | 7.2 HIGH | Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t |
| CVE-2026-92615 | 6.6 MEDIUM | Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena |
| CVE-2026-92358 | 6.4 MEDIUM | Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil |
| CVE-2026-92091 | 5.9 MEDIUM | Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops |
No comments yet