<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:22:34.952157+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348745</id>
    <title>EUVD-2026-348745</title>
    <updated>2026-10-03T14:22:35.003776+00:00</updated>
    <content>EUVD-2026-348745</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-14209</id>
    <title>fkie_cve-2026-14209</title>
    <updated>2026-10-03T14:22:35.003816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific "brute-force-user" endpoint to access a user's full profile. This includes sensitive information and security metadata. The issue occurs because the system fails to check if the administrator has the required "view" permission for that specific user when using this particular search path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-14209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xmfr-m52w-m2hx</id>
    <title>GHSA-xmfr-m52w-m2hx</title>
    <updated>2026-10-03T14:22:35.003854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific "brute-force-user" endpoint to access a user's full profile. This includes sensitive information and security metadata. The issue occurs because the system fails to check if the administrator has the required "view" permission for that specific user when using this particular search path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xmfr-m52w-m2hx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50846</id>
    <title>RHSA-2026:50846 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.14 Security Update</title>
    <updated>2026-10-03T14:22:35.003874+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak: Keycloak: Privilege escalation through hardcoded role mapper injection keycloak: org.keycloak.protocol.oidc: HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 keycloak: Keycloak: Security policy bypass in JWE-encrypted request object processing keycloak: Keycloak: Brute-force protection bypass in CIBA flow keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison keycloak-admin-ui: keycloak-admin-ui:Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions keycloak-services: keycloak-services: FGAP v2 client scope assignment bypass via ClientResource keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter keycloak-services: keycloak-services: DCR protocol mapper type-swap policy bypass allows privilege escalation keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2145</id>
    <title>WID-SEC-W-2026-2145 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:22:35.003929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2145"/>
  </entry>
</feed>
