Threats Tagged 'cve-2026-16104'
View all threats tagged with 'cve-2026-16104'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-16104'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat has released security updates for the Red Hat build of Keycloak 26.6.7 and its Operator for OpenShift. These updates address multiple vulnerabilities including information disclosure, privilege escalation, authorization bypasses, remote code execution, and denial of service issues. The vulnerabilities affect various components such as group hierarchy search, organization invitation links, JWT assertion policies, role authorization, token exchanges, and more. The update aligns with the standalone Keycloak product release and is intended for on-premise or private cloud deployments on OpenShift Container Platform. Join the discussion | GCVE Database | 09/16/2026, 15:46:54 UTC Added: 09/29/2026, 21:04:20 UTC |
Red Hat has issued a security advisory for Red Hat build of Keycloak 26.6.7 addressing multiple vulnerabilities. These include information disclosure, authorization bypasses, privilege escalation, remote code execution, and denial of service issues. The update fixes a wide range of security flaws affecting authentication, authorization, token handling, and administrative functions. The advisory recommends applying the update after backing up existing installations. Join the discussion | GCVE Database | 09/16/2026, 15:45:17 UTC Added: 09/29/2026, 21:04:20 UTC |
0 A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs. Join the discussion | CVE Database V5 | 07/17/2026, 16:43:54 UTC Added: 07/18/2026, 11:08:40 UTC |
Showing 1 to 3 of 3 results