<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:25:56.883168+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-9799</id>
    <title>BIT-keycloak-2026-9799 — Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass</title>
    <updated>2026-10-02T23:25:56.891793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even if they do not have a ticket for those specific resources. This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, where no explicit policy protects the resource type. The primary consequence is unauthorized information disclosure or modification of resources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-9799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815</id>
    <title>certfr-2026-avi-0815 — De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de pro…</title>
    <updated>2026-10-02T23:25:56.891853+00:00</updated>
    <content>certfr-2026-avi-0815</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330496</id>
    <title>EUVD-2026-330496</title>
    <updated>2026-10-02T23:25:56.891874+00:00</updated>
    <content>EUVD-2026-330496</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9799</id>
    <title>fkie_cve-2026-9799</title>
    <updated>2026-10-02T23:25:56.891886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even if they do not have a ticket for those specific resources. This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, where no explicit policy protects the resource type. The primary consequence is unauthorized information disclosure or modification of resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-9799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gfv4-4vr2-rr4g</id>
    <title>GHSA-gfv4-4vr2-rr4g</title>
    <updated>2026-10-02T23:25:56.891909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even if they do not have a ticket for those specific resources. This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, where no explicit policy protects the resource type. The primary consequence is unauthorized information disclosure or modification of resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gfv4-4vr2-rr4g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30049</id>
    <title>RHSA-2026:30049 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.13 Security Update</title>
    <updated>2026-10-02T23:25:56.891926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled keycloak: org.keycloak/keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services keycloak: Keycloak: Information disclosure through arbitrary filesystem path probing keycloak: Keycloak: Cross-site scripting (XSS) via case-insensitive URI validation bypass keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login keycloak: Keycloak: Information disclosure due to user profile permission bypass keycloak: Group-Admin Escalation to Realm-Admin keycloak: Keycloak: Privilege escalation due to oversized subject_token JWT keycloak: Keycloak: Attacker can re-enable and take over disabled clients via Registration Access Token keycloak-rhel9: Organization Data Leak After Feature Disabled in Keycloak keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition keycloak: Keycloak: Information disclosure via SAML ECP endpoint keycloak: Keycloak: Privilege escalation via im…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093</id>
    <title>WID-SEC-W-2026-2093 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:25:56.891971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093"/>
  </entry>
</feed>
