<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:54:34.811571+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-2366</id>
    <title>BIT-keycloak-2026-2366 — Keycloak: keycloak: information disclosure via authorization bypass in admin api</title>
    <updated>2026-10-03T15:54:34.867574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-2366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278832</id>
    <title>EUVD-2026-278832</title>
    <updated>2026-10-03T15:54:34.867630+00:00</updated>
    <content>EUVD-2026-278832</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278832"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2366</id>
    <title>fkie_cve-2026-2366</title>
    <updated>2026-10-03T15:54:34.867646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-2366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r8jr-wg88-fq5c</id>
    <title>GHSA-r8jr-wg88-fq5c — Keycloak vulnerable to authorization bypass via the Admin API</title>
    <updated>2026-10-03T15:54:34.867669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @keycloak/keycloak-admin-client, Maven: org.keycloak:keycloak-js-admin-client</p>
<p>A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r8jr-wg88-fq5c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:6477</id>
    <title>RHSA-2026:6477 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.11 Update</title>
    <updated>2026-10-03T15:54:34.867692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak-services: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure keycloak: Keycloak IDOR in realm client creating/deleting org.keycloak.protocol.oidc: Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition org.keycloak.protocol.oidc: Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri keycloak: Keycloak: Information disclosure via authorization bypass in Admin API keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission keycloak: Keycloak: Information Disclosure via improper role enforcement in UMA 2.0 Protection API org.keycloak.services.resources.account: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API keycloak: Keycloak: Information disclosure due to redirect_uri validation bypass org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint keycloak: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw keycloak: Keycloak: Replay of action tokens via improper handling of single-use entries keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters keycloak: Keycloak: UMA policy bypass allows authen…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:6477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0394</id>
    <title>WID-SEC-W-2026-0394 — Keycloak: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
    <updated>2026-10-03T15:54:34.867732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler, oder entfernter authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0394"/>
  </entry>
</feed>
