Executive brief
A security flaw has been identified in Keycloak, an open-source identity and access management solution used to secure modern applications and services. The vulnerability allows an attacker to bypass security controls and create unauthorized administrative login credentials. If exploited, this could allow an attacker to gain full control over the identity management system, potentially compromising all user accounts and integrated applications.
Technical details
A vulnerability exists in Keycloak's SingleUseObjectProvider, which serves as a global key-value store. The component lacks proper type and namespace isolation, allowing for improper isolation or compartmentalization (CWE-653). An unauthenticated remote attacker can exploit this flaw to forge authorization codes. Successful exploitation enables the generation of access tokens with administrative privileges, resulting in full privilege escalation. The attack requires a high complexity (AC:H) but no prior authentication or user interaction. Red Hat has released patches in versions 26.2.15 and 26.4.11 to address this issue.
Affected products
- Red Hat Red Hat build of Keycloak 26.2 Before 26.2.15-1
- Red Hat Red Hat build of Keycloak 26.4 Before 26.4.11-1
Timeline
- 2026-04-02: disclosed
- 2026-04-02: patched: Fixed in Red Hat build of Keycloak 26.2.15 and 26.4.11
References
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2026:6475
- https://access.redhat.com/errata/RHSA-2026:6476
- https://access.redhat.com/errata/RHSA-2026:6477
- https://access.redhat.com/errata/RHSA-2026:6478
- https://access.redhat.com/security/cve/CVE-2026-4282