Junglewise Threat Intelligence

CVE-2026-3872: Keycloak redirect URI validation bypass via wildcard path manipulation

CVE-2026-3872 · Severity: high · CVSS 7.3 · Published 2026-04-02

Technologies: Red Hat Keycloak, org.keycloak:keycloak-services (Maven). Vendors: Red Hat, Maven.

Executive brief

Keycloak, a popular open-source identity and access management tool, contains a security flaw in how it validates web addresses during the login process. An attacker who controls a specific part of the same web server can trick the system into sending sensitive login tokens to an unauthorized location. This could allow an attacker to impersonate users and gain unauthorized access to protected data and applications.

Technical details

A flaw was discovered in Keycloak's validation of redirect Uniform Resource Identifiers (URIs) when wildcards are employed. An attacker who has control over a different path on the same web server can exploit this logic error to bypass path restrictions. By crafting a malicious request, the attacker can redirect the OAuth2/OpenID Connect flow to an unintended destination, leading to the theft of authorization codes or access tokens. This is classified as an Open Redirect (CWE-601) that specifically impacts the security of the authentication handshake. The issue is addressed in Red Hat build of Keycloak versions 26.2.15 and 26.4.11.

Affected products

  • Red Hat Keycloak 26.2, 26.4, and versions prior to 26.2.15 and 26.4.11

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: patched: Fixed in Red Hat build of Keycloak 26.2.15 and 26.4.11

References

Related threats