<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:57:39.251625+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-11800</id>
    <title>BIT-keycloak-2026-11800 — Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion</title>
    <updated>2026-10-03T17:57:39.330474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-11800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815</id>
    <title>certfr-2026-avi-0815 — De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de pro…</title>
    <updated>2026-10-03T17:57:39.330530+00:00</updated>
    <content>certfr-2026-avi-0815</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337545</id>
    <title>EUVD-2026-337545</title>
    <updated>2026-10-03T17:57:39.330551+00:00</updated>
    <content>EUVD-2026-337545</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-11800</id>
    <title>fkie_cve-2026-11800</title>
    <updated>2026-10-03T17:57:39.330565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-11800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gqj5-2xp5-3qmp</id>
    <title>GHSA-gqj5-2xp5-3qmp</title>
    <updated>2026-10-03T17:57:39.330589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gqj5-2xp5-3qmp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30083</id>
    <title>RHSA-2026:30083 — Red Hat Security Advisory: Red Hat build of Keycloak 26.6.4 Security Update</title>
    <updated>2026-10-03T17:57:39.330605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name keycloak: Keycloak: Information disclosure through arbitrary filesystem path probing keycloak: Keycloak: Cross-site scripting (XSS) via case-insensitive URI validation bypass keycloak: Group-Admin Escalation to Realm-Admin keycloak: Keycloak: Attacker can re-enable and take over disabled clients via Registration Access Token keycloak: Keycloak: Privilege escalation via improper scope mapping enforcement keycloak: Keycloak: Unauthorized access to resources via UMA permission ticket bypass keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison org.keycloak:keycloak-services: Keycloak: Authentication bypass via JWT algorithm confusion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093</id>
    <title>WID-SEC-W-2026-2093 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:57:39.330634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093"/>
  </entry>
</feed>
