<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:43:03.117736+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0159</id>
    <title>certfr-2026-avi-0159 — De multiples vulnérabilités ont été découvertes dans Keycloak. Elles permettent à un attaquant de provoquer un contourn…</title>
    <updated>2026-10-04T04:43:03.177652+00:00</updated>
    <content>certfr-2026-avi-0159</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337533</id>
    <title>EUVD-2026-337533</title>
    <updated>2026-10-04T04:43:03.177698+00:00</updated>
    <content>EUVD-2026-337533</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1486</id>
    <title>fkie_cve-2026-1486</title>
    <updated>2026-10-04T04:43:03.177715+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-1486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-37gf-gmxv-74wv</id>
    <title>GHSA-37gf-gmxv-74wv — Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokens</title>
    <updated>2026-10-04T04:43:03.177751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-services</p>
<p>A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-37gf-gmxv-74wv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:2365</id>
    <title>RHSA-2026:2365 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.9 Security Update</title>
    <updated>2026-10-04T04:43:03.177779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak.services.resources.admin: Keycloak: Limited administrator can retrieve sensitive user attributes via Admin API org.keycloak/keycloak-services: Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users keycloak: Incorrect ownership checks in /uma-policy/ org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators org.keycloak.protocol.oidc.grants: Disabled identity providers are still accepted for JWT Authorization Grant org.keycloak.services.resources.organizations: Keycloak: Unauthorized organization registration via improper invitation token validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:2365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0356</id>
    <title>WID-SEC-W-2026-0356 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-04T04:43:03.177807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um seine Privilegien zu erhöhen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0356"/>
  </entry>
</feed>
