<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:16:39 +0000</lastBuildDate>
    <item>
      <title>BIT-keycloak-2026-11800 — Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-11800</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-11800</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0815 — De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815</link>
      <description>certfr-2026-avi-0815</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0815</guid>
    </item>
    <item>
      <title>EUVD-2026-337545</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337545</link>
      <description>EUVD-2026-337545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337545</guid>
    </item>
    <item>
      <title>fkie_cve-2026-11800</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-11800</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-11800</guid>
    </item>
    <item>
      <title>GHSA-gqj5-2xp5-3qmp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gqj5-2xp5-3qmp</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gqj5-2xp5-3qmp</guid>
    </item>
    <item>
      <title>RHSA-2026:30083 — Red Hat Security Advisory: Red Hat build of Keycloak 26.6.4 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30083</link>
      <description>&lt;p&gt;eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name keycloak: Keycloak: Information disclosure through arbitrary filesystem path probing keycloak: Keycloak: Cross-site scripting (XSS) via case-insensitive URI validation bypass keycloak: Group-Admin Escalation to Realm-Admin keycloak: Keycloak: Attacker can re-enable and take over disabled clients via Registration Access Token keycloak: Keycloak: Privilege escalation via improper scope mapping enforcement keycloak: Keycloak: Unauthorized access to resources via UMA permission ticket bypass keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison org.keycloak:keycloak-services: Keycloak: Authentication bypass via JWT algorithm confusion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name keycloak: Keycloak: Information disclosure through arbitrary filesystem path probing keycloak: Keycloak: Cross-site scripting (XSS) via case-insensitive URI validation bypass keycloak: Group-Admin Escalation to Realm-Admin keycloak: Keycloak: Attacker can re-enable and take over disabled clients via Registration Access Token keycloak: Keycloak: Privilege escalation via improper scope mapping enforcement keycloak: Keycloak: Unauthorized access to resources via UMA permission ticket bypass keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison org.keycloak:keycloak-services: Keycloak: Authentication bypass via JWT algorithm confusion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30083</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2093 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2093</guid>
    </item>
  </channel>
</rss>
