<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:16:23.655252+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-4630</id>
    <title>BIT-keycloak-2026-4630 — Keycloak: keycloak: unauthorized resource access and data modification via insecure direct object reference</title>
    <updated>2026-10-02T21:16:23.707940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-4630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319727</id>
    <title>EUVD-2026-319727</title>
    <updated>2026-10-02T21:16:23.707997+00:00</updated>
    <content>EUVD-2026-319727</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4630</id>
    <title>fkie_cve-2026-4630</title>
    <updated>2026-10-02T21:16:23.708013+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c739-f6xw-6pv2</id>
    <title>GHSA-c739-f6xw-6pv2 — Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers</title>
    <updated>2026-10-02T21:16:23.708038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-services</p>
<p>Keycloak's Authorization Services feature exposes a User-Managed Access Protection API that include an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, an authenticated client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c739-f6xw-6pv2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19596</id>
    <title>RHSA-2026:19596 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.12 Security Update</title>
    <updated>2026-10-02T21:16:23.708061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak-services: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling in Keycloak keycloak: Keycloak: Unauthorized resource access and data modification via Insecure Direct Object Reference keycloak: Keycloak: Denial of Service via specially crafted SAML input org.keycloak/keycloak-services: Open redirect when using wildcard valid redirect URIs in Keycloak org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612</id>
    <title>WID-SEC-W-2026-1612 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:16:23.708089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Sicherheitsvorkehrungen zu umgehen und einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612"/>
  </entry>
</feed>
