Junglewise Threat Intelligence

CVE-2026-4636: Keycloak UMA policy bypass in Protection API

CVE-2026-4636 · Severity: high · CVSS 8.1 · Published 2026-04-02

Technologies: Red Hat build of Keycloak 26.4, org.keycloak:keycloak-services (Maven). Vendors: Red Hat, Maven.

Executive brief

Keycloak is an identity and access management solution used to secure applications and services. A security flaw allows certain authenticated users to bypass protection policies and gain unauthorized access to resources owned by other users. This could lead to the exposure of sensitive information or the performance of unauthorized actions on behalf of other users.

Technical details

A vulnerability in Keycloak's User-Managed Access (UMA) implementation allows an authenticated user with the 'uma_protection' role to bypass policy validation. The flaw exists because the application fails to properly validate resource identifiers within a policy creation request against the resource specified in the URL path. An attacker can include resource IDs belonging to other users in a request targeting their own resource, effectively granting themselves unauthorized permissions. This enables the attacker to obtain a Requesting Party Token (RPT) for victim-owned resources. The issue is classified as CWE-551 (Incorrect Behavior Order: Authorization Before Parsing and Canonicalization) and has been addressed in Red Hat build of Keycloak versions 26.2.15 and 26.4.11.

Affected products

  • Red Hat Red Hat build of Keycloak 26.2 Fixed in 26.2.15-1
  • Red Hat Red Hat build of Keycloak 26.4 Fixed in 26.4.11-1

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: patched: Fixed in Red Hat build of Keycloak 26.2.15 and 26.4.11

References

Related threats