<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:09:23 +0000</lastBuildDate>
    <item>
      <title>BIT-keycloak-2026-16102 — Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-16102</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-16102</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0976 — De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0976</link>
      <description>certfr-2026-avi-0976</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0976</guid>
    </item>
    <item>
      <title>EUVD-2026-361734</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361734</link>
      <description>EUVD-2026-361734</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361734</guid>
    </item>
    <item>
      <title>fkie_cve-2026-16102</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16102</link>
      <description>&lt;p&gt;A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-16102</guid>
    </item>
    <item>
      <title>GHSA-6x4h-v8cp-whwh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6x4h-v8cp-whwh</link>
      <description>&lt;p&gt;A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6x4h-v8cp-whwh</guid>
    </item>
    <item>
      <title>RHSA-2026:50846 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.14 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:50846</link>
      <description>&lt;p&gt;keycloak: Keycloak: Privilege escalation through hardcoded role mapper injection keycloak: org.keycloak.protocol.oidc: HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 keycloak: Keycloak: Security policy bypass in JWE-encrypted request object processing keycloak: Keycloak: Brute-force protection bypass in CIBA flow keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison keycloak-admin-ui: keycloak-admin-ui:Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions keycloak-services: keycloak-services: FGAP v2 client scope assignment bypass via ClientResource keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter keycloak-services: keycloak-services: DCR protocol mapper type-swap policy bypass allows privilege escalation keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak: Keycloak: Privilege escalation through hardcoded role mapper injection keycloak: org.keycloak.protocol.oidc: HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 keycloak: Keycloak: Security policy bypass in JWE-encrypted request object processing keycloak: Keycloak: Brute-force protection bypass in CIBA flow keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison keycloak-admin-ui: keycloak-admin-ui:Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions keycloak-services: keycloak-services: FGAP v2 client scope assignment bypass via ClientResource keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter keycloak-services: keycloak-services: DCR protocol mapper type-swap policy bypass allows privilege escalation keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:50846</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2677 — RedHat Build of Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2677</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Administratorrechte zu erlangen, Benutzerkonten zu übernehmen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Administratorrechte zu erlangen, Benutzerkonten zu übernehmen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2677</guid>
    </item>
  </channel>
</rss>
