Threats Tagged 'bit-keycloak-2026-16102'
View all threats tagged with 'bit-keycloak-2026-16102'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bit-keycloak-2026-16102'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-16102 is a vulnerability in the Dynamic Client Registration (DCR) component of the Red Hat build of Keycloak 26.4. The default DCR policy does not properly validate claim paths for User Property mappers, enabling attackers with standard user accounts and limited Initial Access Tokens to forge administrative roles in their access tokens. This flaw allows attackers to take over clients, steal confidential secrets, and potentially gain full administrative control over the realm. Red Hat has rated this vulnerability as Important with a CVSS score of 8.1 (high severity). Join the discussion | GCVE Database | 08/05/2026, 13:50:50 UTC Added: 08/05/2026, 18:46:59 UTC |
Showing 1 to 1 of 1 result