Technology · Red Hat
Red Hat Build of Keycloak vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 54 vulnerabilities in Red Hat Build of Keycloak: 0 in the last 7 days and 20 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18218, was published on 31 July 2026.
- Last 7 days
- 0
- Last 90 days
- 20
- Critical, all time
- 1
- Exploited in the wild
- 0
About Red Hat Build of Keycloak
Red Hat build of Keycloak is an open-source identity and access management solution providing single sign-on and identity brokering.
Latest Red Hat Build of Keycloak vulnerabilities
- CVE-2026-18218: Keycloak TokenManager revocation bypass via client not-before policymediumCVSS 4.2
- CVE-2026-18217: Keycloak SAML HTTP Parameter Pollution in HTTP-Redirect bindinglowCVSS 3.4
- CVE-2026-18211: Keycloak secure-client-uris policy bypass via improper host validationmediumCVSS 4.2
- CVE-2026-18209: Keycloak OIDC parameter pollution via redirect URI fragmentlowCVSS 3.4
- CVE-2026-18206: Keycloak keycloak-services improper wildcard domain validation in client policieslowCVSS 3.7
- CVE-2026-18207: Keycloak improper authorization in client policy enforcementmediumCVSS 6.5
- CVE-2026-17059: Keycloak keycloak-services authorization bypass in role-users endpointmediumCVSS 6.5
- CVE-2026-16106: Keycloak missing authorization in admin REST API role managementmediumCVSS 4.9
- CVE-2026-16104: Red Hat Build of Keycloak Information Exposure in Authentication ConfigmediumCVSS 4.3
- CVE-2026-16103: Red Hat Keycloak brute-force protection bypass in CIBA token redemptionmediumCVSS 4.3
- CVE-2026-16089: Red Hat Build of Keycloak authorization code retargeting in keycloak-servicesmediumCVSS 5.4
- CVE-2026-16072: Keycloak permission bypass in organization management componentmediumCVSS 4.9
- CVE-2026-15943: Keycloak improper validation of OIDC secret masking in keycloak-servicesmediumCVSS 5.5
- CVE-2026-15945: Red Hat Keycloak authorization bypass in group search APImediumCVSS 4.3
- CVE-2026-14781: Red Hat Keycloak improper validation of email_verified claim in OIDC brokermediumCVSS 4.8
- CVE-2026-14615: Red Hat Keycloak authorization bypass in FGAP v2 child group endpointmediumCVSS 4.3
- CVE-2026-14613: Keycloak information disclosure in FGAP v2 role groups endpointmediumCVSS 4.3
- CVE-2026-4629: Keycloak privilege escalation via hardcoded role mapper injectionmediumCVSS 6.5
- CVE-2026-14209: Keycloak Admin UI auth bypass in brute-force-user endpointmediumCVSS 4.3
- CVE-2026-12388: Keycloak privilege escalation in Identity Provider mappermediumCVSS 6.5
- CVE-2026-11800: Keycloak JWT algorithm confusion in JWT Authorization Grant flowhighCVSS 8.1
- CVE-2026-9800: Keycloak Policy Enforcer authorization bypass via incorrect URI comparisonhighCVSS 8.1
- CVE-2026-9705: Keycloak security bypass in client registration servicemediumCVSS 6.5
- CVE-2026-9099: Keycloak privilege escalation via missing authorization in GroupResourcehighCVSS 7.7
- CVE-2026-9086: Keycloak XSS via case-insensitive URI validation bypasshighCVSS 7.3
Most severe Red Hat Build of Keycloak vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33228: WebReflection flatted prototype pollution in parse functioncriticalCVSS 9.8EPSS 1.0%
- CVE-2026-3047: Keycloak SAML broker authentication bypass via disabled clienthighCVSS 8.8EPSS 0.9%
- CVE-2026-7504: Red Hat Keycloak open redirect via URL validation bypasshighCVSS 8.1EPSS 0.5%
- CVE-2026-4636: Keycloak UMA policy bypass in Protection APIhighCVSS 8.1EPSS 0.5%
- CVE-2026-1529: Keycloak improper signature verification in organization invitationshighCVSS 8.1EPSS 0.5%
- CVE-2026-11800: Keycloak JWT algorithm confusion in JWT Authorization Grant flowhighCVSS 8.1
- CVE-2026-9800: Keycloak Policy Enforcer authorization bypass via incorrect URI comparisonhighCVSS 8.1
- CVE-2026-9099: Keycloak privilege escalation via missing authorization in GroupResourcehighCVSS 7.7
- CVE-2026-7307: Keycloak denial of service in SAML endpointhighCVSS 7.5EPSS 0.9%
- CVE-2026-7507: Keycloak session fixation in login-actions endpointshighCVSS 7.5EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 6 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 7 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Build of Keycloak vulnerabilities", https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak, 27 September 2026.