在 Keycloak(一种身份和访问管理解决方案)的身份验证会话管理中发现了漏洞。该问题发生在管理员通过客户端策略强制实施更强的身份验证流程(例如强制设置双因素认证(2FA))时。用户在登录过程中手动访问特定的会话重启 Web 链接即可绕过该要求。此操作会清除用于跟踪所需安全步骤的内部标记,从而使用户仅使用密码即可登录,而无需完成强制的 2FA 设置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15801 | 8.0 HIGH | Cri-o: cri-o: insufficient validation during container checkpoint restore |
| CVE-2026-94215 | 5.5 MEDIUM | Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach |
| CVE-2026-94213 | 4.9 MEDIUM | Keycloak-services: keycloak-services: authorization services policy evaluation endpoint le |
| CVE-2026-94217 | 3.5 LOW | Keycloak-services: keycloak-services: uma scope merge across resource owners via resource |
No comments yet