<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:34:50.095878+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-9083</id>
    <title>BIT-keycloak-2026-9083 — Keycloak: keycloak: information disclosure through arbitrary filesystem path probing</title>
    <updated>2026-10-03T00:34:50.106392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-9083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815</id>
    <title>certfr-2026-avi-0815 — De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de pro…</title>
    <updated>2026-10-03T00:34:50.106452+00:00</updated>
    <content>certfr-2026-avi-0815</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330491</id>
    <title>EUVD-2026-330491</title>
    <updated>2026-10-03T00:34:50.106473+00:00</updated>
    <content>EUVD-2026-330491</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9083</id>
    <title>fkie_cve-2026-9083</title>
    <updated>2026-10-03T00:34:50.106485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-9083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7pm9-g8jh-3m74</id>
    <title>GHSA-7pm9-g8jh-3m74</title>
    <updated>2026-10-03T00:34:50.106509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and are readable by the Keycloak process. This information disclosure could be used to identify high-value targets for follow-on attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7pm9-g8jh-3m74"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30049</id>
    <title>RHSA-2026:30049 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.13 Security Update</title>
    <updated>2026-10-03T00:34:50.106525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled keycloak: org.keycloak/keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services keycloak: Keycloak: Information disclosure through arbitrary filesystem path probing keycloak: Keycloak: Cross-site scripting (XSS) via case-insensitive URI validation bypass keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login keycloak: Keycloak: Information disclosure due to user profile permission bypass keycloak: Group-Admin Escalation to Realm-Admin keycloak: Keycloak: Privilege escalation due to oversized subject_token JWT keycloak: Keycloak: Attacker can re-enable and take over disabled clients via Registration Access Token keycloak-rhel9: Organization Data Leak After Feature Disabled in Keycloak keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition keycloak: Keycloak: Information disclosure via SAML ECP endpoint keycloak: Keycloak: Privilege escalation via im…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093</id>
    <title>WID-SEC-W-2026-2093 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-03T00:34:50.106576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093"/>
  </entry>
</feed>
