Keycloak是Keycloak组织开源的一款身份认证与权限管理平台。 Keycloak存在授权问题漏洞,该漏洞源于授权服务的组策略提供程序在评估基于组的策略时使用仅包含组名而非完整路径的令牌,导致不同组织部分中的同名组被混淆,将未授权用户误认为授权组成员,可能允许用户未经授权访问受保护资源。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Single Sign-On 7 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12564 | 9.6 CRITICAL | Automation-controller: automation-controller: kubernetes service account token exfiltratio |
| CVE-2026-18963 | 9.1 CRITICAL | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentia |
| CVE-2026-66793 | 8.8 HIGH | Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary containe |
| CVE-2026-75924 | 8.7 HIGH | Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants clust |
| CVE-2026-71365 | 7.7 HIGH | Awx: webhook status callback ssrf leaks the git pat |
| CVE-2026-15571 | 7.3 HIGH | Keycloak-services: keycloak-services: predictable account-linking hash enables account tak |
| CVE-2026-66780 | 6.5 MEDIUM | Submariner-operator: broker serviceaccount secret (token + ca) logged in full at trace ver |
| CVE-2026-75032 | 6.3 MEDIUM | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder |
| CVE-2026-66782 | 5.8 MEDIUM | Submariner-operator: operator clusterrole grants cluster-wide create/update on all configm |
| CVE-2026-75485 | 5.5 MEDIUM | Must-gather: /tmp/kubeconfig retention |
| CVE-2026-73834 | 5.5 MEDIUM | Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redact |
| CVE-2026-66781 | 5.4 MEDIUM | Submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authe |
| CVE-2026-66783 | 4.4 MEDIUM | Submariner-operator: release workflow consumes same-org composite action via mutable @deve |
No comments yet