在 Keycloak(一个开源的身份与访问管理方案)的管理 REST API 中发现了一个缺陷。用于删除用户凭据的端点未能正确检查细粒度的“重置密码”权限。这使得本应被限制在重置密码的委托管理员能够删除用户的密码凭据,从而导致该用户无法登录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94000 | 6.6 MEDIUM | Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to re |
| CVE-2026-93999 | 4.2 MEDIUM | Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled |
No comments yet