<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:03:06 +0000</lastBuildDate>
    <item>
      <title>BIT-keycloak-2026-17048 — Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-17048</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-17048</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1078 — De multiples vulnérabilités ont été découvertes dans Keycloak. Elles permettent à un attaquant de provoquer un contourn…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078</link>
      <description>certfr-2026-avi-1078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078</guid>
    </item>
    <item>
      <title>EUVD-2026-355274</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355274</link>
      <description>EUVD-2026-355274</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355274</guid>
    </item>
    <item>
      <title>fkie_cve-2026-17048</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-17048</link>
      <description>&lt;p&gt;A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-17048</guid>
    </item>
    <item>
      <title>GHSA-p3wj-5684-x596</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p3wj-5684-x596</link>
      <description>&lt;p&gt;A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p3wj-5684-x596</guid>
    </item>
    <item>
      <title>NCSC-2026-0326 — Kwetsbaarheden verholpen in Keycloak</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0326</link>
      <description>NCSC-2026-0326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0326</guid>
    </item>
    <item>
      <title>RHSA-2026:56523 — Red Hat Security Advisory: Red Hat build of Keycloak 26.6.6 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:56523</link>
      <description>&lt;p&gt;keycloak: Keycloak: Privilege escalation via Time-of-Check to Time-of-Use (TOCTOU) vulnerability keycloak-services: keycloak-services: Keycloak: FGAP v2 role groups endpoint discloses hidden group metadata without group view permission keycloak-services: keycloak-services: Predictable account-linking hash enables account takeover via malicious OIDC client keycloak-services: keycloak-services: Vault-resolved rotated client secrets leaked via Admin REST API keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak: Keycloak: Privilege escalation via Time-of-Check to Time-of-Use (TOCTOU) vulnerability keycloak-services: keycloak-services: Keycloak: FGAP v2 role groups endpoint discloses hidden group metadata without group view permission keycloak-services: keycloak-services: Predictable account-linking hash enables account takeover via malicious OIDC client keycloak-services: keycloak-services: Vault-resolved rotated client secrets leaked via Admin REST API keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:56523</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2517 — Keycloak: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2517</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2517</guid>
    </item>
  </channel>
</rss>
