在身份和访问管理解决方案 Keycloak 的认证级别强制机制中发现了一个缺陷。当客户端要求已处于较低安全级别会话中的用户提升安全级别时,问题就会出现。由于会话重新评估处理逻辑存在错误,Keycloak 可能会错误地颁发较低安全级别的令牌,而非强制实施所需的高安全级别,从而可能导致未经授权访问依赖于这些安全声明的敏感资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90959 | 8.1 HIGH | Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enabl |
| CVE-2026-95521 | 7.8 HIGH | Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i |
| CVE-2026-95519 | 7.8 HIGH | Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m |
| CVE-2026-97185 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file |
| CVE-2026-94416 | 6.8 MEDIUM | Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery |
| CVE-2026-97177 | 6.6 MEDIUM | Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p |
| CVE-2026-97311 | 4.3 MEDIUM | Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups |
No comments yet