在 Keycloak Admin REST API 的用户更新机制中发现了一个漏洞。当启用细粒度管理员权限(Fine-Grained Admin Permissions)时,系统在更新普通用户资料时未能检查特定的密码重置授权。这导致一个本应被限制执行密码重置操作的委派管理员,可以更改用户凭证并接管其账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90959 | 8.1 HIGH | Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enabl |
| CVE-2026-95521 | 7.8 HIGH | Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i |
| CVE-2026-95519 | 7.8 HIGH | Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m |
| CVE-2026-97185 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file |
| CVE-2026-94416 | 6.8 MEDIUM | Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery |
| CVE-2026-97311 | 4.3 MEDIUM | Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups |
| CVE-2026-97176 | 4.2 MEDIUM | Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook |
No comments yet