A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. (CVE-2026-16071)
A vulnerability in the LDAP storage provider of Keycloak allows delegated administrators to perform LDAP searches using specific Distinguished Names (DNs) without proper validation. This flaw enables lookups for users outside the configured search boundary, potentially disclosing account information from unauthorized directory parts and causing unintended user imports into local storage. The issue requires delegated administrative privileges to exploit and has been assessed with moderate severity.
AI Analysis
Technical Summary
CVE-2026-16071 is a vulnerability in Keycloak's LDAP storage provider that arises from missing validation of LDAP Distinguished Names during delegated administrator searches. This lack of boundary validation permits lookups for users located outside the configured LDAP search boundary, resulting in unauthorized disclosure of user account details and unintended importing of those users into Keycloak's local storage. The vulnerability requires an attacker to have delegated administrative privileges and does not involve user interaction. It has a CVSS v3.1 base score of 5.4 (medium severity) with low confidentiality and integrity impacts and no availability impact. The root cause is the failure to ensure that requested LDAP DNs fall within the provider's configured search boundary.
Potential Impact
Successful exploitation allows an attacker with delegated administrative privileges to disclose user account information from unauthorized LDAP organizational units and cause unintended user imports into the local Keycloak database. This could lead to unauthorized access to user data outside the intended LDAP search scope. The impact on confidentiality and integrity is low, and there is no impact on availability.
Mitigation Recommendations
As of the current information, no explicit patch or fix version is provided. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance. Since exploitation requires delegated administrative privileges, restricting and monitoring delegated admin roles can reduce risk. Follow updates from Red Hat and Keycloak for forthcoming patches or official fixes.
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. (CVE-2026-16071)
Description
A vulnerability in the LDAP storage provider of Keycloak allows delegated administrators to perform LDAP searches using specific Distinguished Names (DNs) without proper validation. This flaw enables lookups for users outside the configured search boundary, potentially disclosing account information from unauthorized directory parts and causing unintended user imports into local storage. The issue requires delegated administrative privileges to exploit and has been assessed with moderate severity.
CVSS v3.1
Score 5.4medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16071 is a vulnerability in Keycloak's LDAP storage provider that arises from missing validation of LDAP Distinguished Names during delegated administrator searches. This lack of boundary validation permits lookups for users located outside the configured LDAP search boundary, resulting in unauthorized disclosure of user account details and unintended importing of those users into Keycloak's local storage. The vulnerability requires an attacker to have delegated administrative privileges and does not involve user interaction. It has a CVSS v3.1 base score of 5.4 (medium severity) with low confidentiality and integrity impacts and no availability impact. The root cause is the failure to ensure that requested LDAP DNs fall within the provider's configured search boundary.
Potential Impact
Successful exploitation allows an attacker with delegated administrative privileges to disclose user account information from unauthorized LDAP organizational units and cause unintended user imports into the local Keycloak database. This could lead to unauthorized access to user data outside the intended LDAP search scope. The impact on confidentiality and integrity is low, and there is no impact on availability.
Mitigation Recommendations
As of the current information, no explicit patch or fix version is provided. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance. Since exploitation requires delegated administrative privileges, restricting and monitoring delegated admin roles can reduce risk. Follow updates from Red Hat and Keycloak for forthcoming patches or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-m28w-c4hx-9fvg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-16071"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a738521bf8831d5394efa6a
Added to database: 08/05/2026, 18:46:57 UTC
Last enriched: 08/05/2026, 22:16:59 UTC
Last updated: 08/06/2026, 03:40:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.