<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:17:45 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0159 — De multiples vulnérabilités ont été découvertes dans Keycloak. Elles permettent à un attaquant de provoquer un contourn…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0159</link>
      <description>certfr-2026-avi-0159</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0159</guid>
    </item>
    <item>
      <title>EUVD-2026-337533</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337533</link>
      <description>EUVD-2026-337533</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337533</guid>
    </item>
    <item>
      <title>fkie_cve-2026-1486</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1486</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP&amp;#39;s signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP&amp;#39;s signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-1486</guid>
    </item>
    <item>
      <title>GHSA-37gf-gmxv-74wv — Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokens</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-37gf-gmxv-74wv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP&amp;#39;s signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP&amp;#39;s signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-37gf-gmxv-74wv</guid>
    </item>
    <item>
      <title>RHSA-2026:2365 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.9 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:2365</link>
      <description>&lt;p&gt;org.keycloak.services.resources.admin: Keycloak: Limited administrator can retrieve sensitive user attributes via Admin API org.keycloak/keycloak-services: Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users keycloak: Incorrect ownership checks in /uma-policy/ org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators org.keycloak.protocol.oidc.grants: Disabled identity providers are still accepted for JWT Authorization Grant org.keycloak.services.resources.organizations: Keycloak: Unauthorized organization registration via improper invitation token validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.keycloak.services.resources.admin: Keycloak: Limited administrator can retrieve sensitive user attributes via Admin API org.keycloak/keycloak-services: Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users keycloak: Incorrect ownership checks in /uma-policy/ org.keycloak/keycloak-services: Keycloak: Unauthorized modification of unmanaged user attributes by administrators org.keycloak.protocol.oidc.grants: Disabled identity providers are still accepted for JWT Authorization Grant org.keycloak.services.resources.organizations: Keycloak: Unauthorized organization registration via improper invitation token validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:2365</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0356 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0356</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um seine Privilegien zu erhöhen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um seine Privilegien zu erhöhen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0356</guid>
    </item>
  </channel>
</rss>
