Technology · Red Hat
Red Hat Keycloak vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 48 vulnerabilities in Red Hat Keycloak: 2 in the last 7 days and 28 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-97846, was published on 25 September 2026.
- Last 7 days
- 2
- Last 90 days
- 28
- Critical, all time
- 1
- Exploited in the wild
- 0
About Red Hat Keycloak
An open source identity and access management solution providing authentication and authorization services.
Latest Red Hat Keycloak vulnerabilities
- CVE-2026-97846: Keycloak mTLS holder-of-key binding bypass in Standard Token ExchangemediumCVSS 6.8EPSS 0.1%
- CVE-2026-96446: Keycloak Pushed Authorization Request URI reuse in silent authenticationmediumCVSS 4.2EPSS 0.2%
- CVE-2026-79652: Red Hat Build of Keycloak JWT Bearer authorization bypassmediumCVSS 5.9EPSS 0.3%
- CVE-2026-18569: Red Hat Keycloak backchannel logout signature bypasslowCVSS 3.7EPSS 0.3%
- CVE-2026-18218: Keycloak TokenManager revocation bypass via client not-before policymediumCVSS 4.2
- CVE-2026-18215: Keycloak authentication bypass in Microsoft token exchangemediumCVSS 6.8
- CVE-2026-18214: Keycloak domain restriction bypass in Google token exchangemediumCVSS 6.8
- CVE-2026-18211: Keycloak secure-client-uris policy bypass via improper host validationmediumCVSS 4.2
- CVE-2026-18209: Keycloak OIDC parameter pollution via redirect URI fragmentlowCVSS 3.4
- CVE-2026-18208: Keycloak information disclosure in OIDC token introspection endpointmediumCVSS 6.5
- CVE-2026-18206: Keycloak keycloak-services improper wildcard domain validation in client policieslowCVSS 3.7
- CVE-2026-18203: Keycloak Incorrect Authorization via Group Path Prefix MatchingmediumCVSS 6.5
- CVE-2026-16105: Keycloak improper authorization in RoleContainerResource composite endpointsmediumCVSS 4.9
- CVE-2026-18207: Keycloak improper authorization in client policy enforcementmediumCVSS 6.5
- CVE-2026-16108: Red Hat Keycloak information disclosure in default-groups REST endpointmediumCVSS 4.3
- CVE-2026-16106: Keycloak missing authorization in admin REST API role managementmediumCVSS 4.9
- CVE-2026-16104: Red Hat Build of Keycloak Information Exposure in Authentication ConfigmediumCVSS 4.3
- CVE-2026-16103: Red Hat Keycloak brute-force protection bypass in CIBA token redemptionmediumCVSS 4.3
- CVE-2026-16093: Red Hat Keycloak Client Policy bypass in keycloak-servicesmediumCVSS 5.4
- CVE-2026-16089: Red Hat Build of Keycloak authorization code retargeting in keycloak-servicesmediumCVSS 5.4
- CVE-2026-16072: Keycloak permission bypass in organization management componentmediumCVSS 4.9
- CVE-2026-15943: Keycloak improper validation of OIDC secret masking in keycloak-servicesmediumCVSS 5.5
- CVE-2026-15945: Red Hat Keycloak authorization bypass in group search APImediumCVSS 4.3
- CVE-2026-14781: Red Hat Keycloak improper validation of email_verified claim in OIDC brokermediumCVSS 4.8
- CVE-2026-14614: Red Hat Keycloak authorization bypass in ClientResource scope assignmentmediumCVSS 5.4
Most severe Red Hat Keycloak vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33228: WebReflection flatted prototype pollution in parse functioncriticalCVSS 9.8EPSS 1.0%
- CVE-2026-1486: Keycloak improper security check for disabled Identity ProvidershighCVSS 8.8EPSS 0.5%
- CVE-2026-7504: Red Hat Keycloak open redirect via URL validation bypasshighCVSS 8.1EPSS 0.5%
- CVE-2026-3009: Keycloak authentication bypass via disabled Identity ProviderhighCVSS 8.1EPSS 0.5%
- CVE-2026-11800: Keycloak JWT algorithm confusion in JWT Authorization Grant flowhighCVSS 8.1
- CVE-2026-2092: Keycloak improper validation of encrypted SAML assertionshighCVSS 7.7EPSS 0.3%
- CVE-2026-7507: Keycloak session fixation in login-actions endpointshighCVSS 7.5EPSS 0.8%
- CVE-2026-4634: Keycloak Denial of Service via OIDC scope parameterhighCVSS 7.5EPSS 0.7%
- CVE-2026-7571: Red Hat Keycloak implicit flow bypass and token disclosurehighCVSS 7.1EPSS 0.4%
- CVE-2026-9704: Keycloak privilege escalation via oversized subject_token JWTmediumCVSS 6.8EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 5 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 9 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 10 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 2 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/build-of-keycloak.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Keycloak vulnerabilities", https://junglewise.ai/threats/technologies/build-of-keycloak, 26 September 2026.