在 Keycloak 的用户管理型访问(UMA,User-Managed Access)实现中发现了一个缺陷。该问题出现在授权令牌端点处理权限票据(permission tickets)的过程中。当两个不同用户拥有同名资源时,如果其中一个用户请求授权令牌,系统会错误地合并这两个资源的权限。这使得攻击者能够获取到本不应被共享的受害者资源上的访问范围(scopes)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15801 | 8.0 HIGH | Cri-o: cri-o: insufficient validation during container checkpoint restore |
| CVE-2026-94215 | 5.5 MEDIUM | Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach |
| CVE-2026-94213 | 4.9 MEDIUM | Keycloak-services: keycloak-services: authorization services policy evaluation endpoint le |
| CVE-2026-94218 | 3.1 LOW | Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication sess |
No comments yet