<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:40:33.294169+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-17048</id>
    <title>BIT-keycloak-2026-17048 — Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api</title>
    <updated>2026-10-02T18:40:33.378896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-17048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078</id>
    <title>certfr-2026-avi-1078 — De multiples vulnérabilités ont été découvertes dans Keycloak. Elles permettent à un attaquant de provoquer un contourn…</title>
    <updated>2026-10-02T18:40:33.378952+00:00</updated>
    <content>certfr-2026-avi-1078</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355274</id>
    <title>EUVD-2026-355274</title>
    <updated>2026-10-02T18:40:33.378975+00:00</updated>
    <content>EUVD-2026-355274</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-17048</id>
    <title>fkie_cve-2026-17048</title>
    <updated>2026-10-02T18:40:33.378988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-17048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p3wj-5684-x596</id>
    <title>GHSA-p3wj-5684-x596</title>
    <updated>2026-10-02T18:40:33.379011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p3wj-5684-x596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0326</id>
    <title>NCSC-2026-0326 — Kwetsbaarheden verholpen in Keycloak</title>
    <updated>2026-10-02T18:40:33.379027+00:00</updated>
    <content>NCSC-2026-0326</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0326"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:56523</id>
    <title>RHSA-2026:56523 — Red Hat Security Advisory: Red Hat build of Keycloak 26.6.6 Security Update</title>
    <updated>2026-10-02T18:40:33.379052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak: Keycloak: Privilege escalation via Time-of-Check to Time-of-Use (TOCTOU) vulnerability keycloak-services: keycloak-services: Keycloak: FGAP v2 role groups endpoint discloses hidden group metadata without group view permission keycloak-services: keycloak-services: Predictable account-linking hash enables account takeover via malicious OIDC client keycloak-services: keycloak-services: Vault-resolved rotated client secrets leaked via Admin REST API keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:56523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2517</id>
    <title>WID-SEC-W-2026-2517 — Keycloak: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
    <updated>2026-10-02T18:40:33.379076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2517"/>
  </entry>
</feed>
