<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:55:16.421965+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330493</id>
    <title>EUVD-2026-330493</title>
    <updated>2026-10-02T23:55:16.451278+00:00</updated>
    <content>EUVD-2026-330493</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9791</id>
    <title>fkie_cve-2026-9791</title>
    <updated>2026-10-02T23:55:16.451335+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-9791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4q93-v92x-p89f</id>
    <title>GHSA-4q93-v92x-p89f — Keycloak Vulnerable to Incorrect Authorization</title>
    <updated>2026-10-02T23:55:16.451369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-server-spi-private, Maven: org.keycloak:keycloak-services</p>
<p>A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after an administrator has explicitly disabled the Organizations feature, potentially leading to incorrect authorization decisions by resource servers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4q93-v92x-p89f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:25097</id>
    <title>RHSA-2026:25097 — Red Hat Security Advisory: Red Hat build of Keycloak 26.6.3 Images Update</title>
    <updated>2026-10-02T23:55:16.451401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled keycloak: org.keycloak/keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login keycloak: Keycloak: Information disclosure due to user profile permission bypass keycloak: Keycloak: Privilege escalation due to oversized subject_token JWT keycloak-rhel9: Organization Data Leak After Feature Disabled in Keycloak keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition keycloak: Keycloak: Information disclosure via SAML ECP endpoint keycloak: Keycloak: Denial of Service via malformed LDAP password policy response keycloak: Keycloak: Unauthorized account access via replayed refresh tokens after cluster restart keycloak: Keycloak: Denial of Service via malformed Authorization header keycloak: org.keycloak.protocol.oidc.grants.ciba: Keycloak: Information disclosure via CORS header injection due to unvalidated JWT azp claim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:25097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1708</id>
    <title>WID-SEC-W-2026-1708 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:55:16.451445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1708"/>
  </entry>
</feed>
