Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.keycloak/keycloak

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-7571 is a vulnerability in Red Hat build of Keycloak 26.4 where a low-privilege user can bypass a security control designed to disable the implicit flow in OpenID Connect clients. By manipulating client data during a session restart, the attacker can obtain access tokens that should be unavailable. These tokens may also be exposed in server logs, proxy logs, and HTTP Referrer headers, leading to sensitive information disclosure. The vulnerability has a CVSS score of 7.1, indicating high severity. Red Hat has released updated packages (Keycloak 26.4.12) addressing this and other related security issues. Users are advised to apply these updates after backing up their installations.

Join the discussion

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection or cookie ownership validation—an attacker can reset the authentication flow state. This causes Single Sign-On (SSO) to authenticate the victim transparently upon clicking the link, allowing the attacker to hijack the required-action form without needing the victim's credentials. A successful exploit could lead to complete account takeover, including highly privileged administrative accounts.

Join the discussion

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.

Join the discussion

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.

Join the discussion

CVE-2026-4630 is an authorization bypass vulnerability in Red Hat build of Keycloak 26.4. An authenticated client can exploit an Insecure Direct Object Reference (IDOR) in the Authorization Services Protection API endpoint by using another resource server's UUID within the same realm. This allows unauthorized GET, PUT, and DELETE operations on resources, potentially leading to information disclosure and unauthorized data modification or deletion. Red Hat has released Keycloak 26.4.12 to address this issue. Users should update to this fixed version to remediate the vulnerability.

Join the discussion

CVE-2026-37981 is a medium severity vulnerability in Red Hat build of Keycloak 26.4 that involves broken access control in the Account Resources user lookup endpoint. It allows a remote authenticated user who owns at least one User-Managed Access (UMA) resource to enumerate and harvest personally identifiable information (PII) of all users in the realm by sending crafted requests with arbitrary usernames or email values. Red Hat has released an updated package, Keycloak 26.4.12, that addresses this vulnerability along with others. Users are advised to back up their installations and apply the update. No known exploits are reported in the wild at this time.

Join the discussion

CVE-2026-37978 is a medium severity vulnerability in Red Hat build of Keycloak 26.4 where a low-privilege administrator with the 'view-clients' role can exploit the 'evaluate-scopes' Admin API endpoint by supplying an arbitrary user ID. This flaw allows unauthorized disclosure of personally identifiable information (PII) across user roles within the realm. The vulnerability can be exploited remotely via network access to the Admin API. Red Hat has released security updates in version 26.4.12 addressing this and other vulnerabilities. Users are advised to apply the update after backing up their installations.

Join the discussion

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.

Join the discussion

CVE-2026-18963 is a critical vulnerability in the reset-credentials flow of the keycloak-services component in Red Hat build of Keycloak 26.4. This flaw allows an unauthenticated attacker to bypass the required email verification step and directly reset the password of any user, potentially gaining full control over their accounts. The vulnerability affects multiple versions prior to 26.4.15, 26.6.6, and 26.7.2. Red Hat has released security updates to address this issue.

Join the discussion

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.

Join the discussion

Showing 1 to 10 of 30 results

Filters:Package: pkg:maven/org.keycloak/keycloak
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses