<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:02:06.909726+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-37981</id>
    <title>BIT-keycloak-2026-37981 — Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint</title>
    <updated>2026-10-03T15:02:06.982251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-37981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319732</id>
    <title>EUVD-2026-319732</title>
    <updated>2026-10-03T15:02:06.982308+00:00</updated>
    <content>EUVD-2026-319732</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-37981</id>
    <title>fkie_cve-2026-37981</title>
    <updated>2026-10-03T15:02:06.982324+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-37981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-933f-rg6j-f46p</id>
    <title>GHSA-933f-rg6j-f46p — Keycloak Account Resources user lookup contains broken access control</title>
    <updated>2026-10-03T15:02:06.982349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-services</p>
<p>Keycloak's Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-933f-rg6j-f46p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19596</id>
    <title>RHSA-2026:19596 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.12 Security Update</title>
    <updated>2026-10-03T15:02:06.982374+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak-services: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling in Keycloak keycloak: Keycloak: Unauthorized resource access and data modification via Insecure Direct Object Reference keycloak: Keycloak: Denial of Service via specially crafted SAML input org.keycloak/keycloak-services: Open redirect when using wildcard valid redirect URIs in Keycloak org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612</id>
    <title>WID-SEC-W-2026-1612 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:02:06.982406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Sicherheitsvorkehrungen zu umgehen und einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612"/>
  </entry>
</feed>
