<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:40:10 +0000</lastBuildDate>
    <item>
      <title>BIT-keycloak-2026-2366 — Keycloak: keycloak: information disclosure via authorization bypass in admin api</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-2366</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim&amp;#39;s unique identifier (UUID) and the Organizations feature is enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim&amp;#39;s unique identifier (UUID) and the Organizations feature is enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-2366</guid>
    </item>
    <item>
      <title>EUVD-2026-278832</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278832</link>
      <description>EUVD-2026-278832</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278832</guid>
    </item>
    <item>
      <title>fkie_cve-2026-2366</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2366</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim&amp;#39;s unique identifier (UUID) and the Organizations feature is enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim&amp;#39;s unique identifier (UUID) and the Organizations feature is enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-2366</guid>
    </item>
    <item>
      <title>GHSA-r8jr-wg88-fq5c — Keycloak vulnerable to authorization bypass via the Admin API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r8jr-wg88-fq5c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @keycloak/keycloak-admin-client, Maven: org.keycloak:keycloak-js-admin-client&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim&amp;#39;s unique identifier (UUID) and the Organizations feature is enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @keycloak/keycloak-admin-client, Maven: org.keycloak:keycloak-js-admin-client&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim&amp;#39;s unique identifier (UUID) and the Organizations feature is enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r8jr-wg88-fq5c</guid>
    </item>
    <item>
      <title>RHSA-2026:6477 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.11 Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:6477</link>
      <description>&lt;p&gt;keycloak-services: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure keycloak: Keycloak IDOR in realm client creating/deleting org.keycloak.protocol.oidc: Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition org.keycloak.protocol.oidc: Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri keycloak: Keycloak: Information disclosure via authorization bypass in Admin API keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission keycloak: Keycloak: Information Disclosure via improper role enforcement in UMA 2.0 Protection API org.keycloak.services.resources.account: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API keycloak: Keycloak: Information disclosure due to redirect_uri validation bypass org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint keycloak: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw keycloak: Keycloak: Replay of action tokens via improper handling of single-use entries keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters keycloak: Keycloak: UMA policy bypass allows authen…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak-services: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure keycloak: Keycloak IDOR in realm client creating/deleting org.keycloak.protocol.oidc: Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition org.keycloak.protocol.oidc: Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri keycloak: Keycloak: Information disclosure via authorization bypass in Admin API keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission keycloak: Keycloak: Information Disclosure via improper role enforcement in UMA 2.0 Protection API org.keycloak.services.resources.account: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API keycloak: Keycloak: Information disclosure due to redirect_uri validation bypass org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint keycloak: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw keycloak: Keycloak: Replay of action tokens via improper handling of single-use entries keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters keycloak: Keycloak: UMA policy bypass allows authen…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:6477</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0394 — Keycloak: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0394</link>
      <description>&lt;p&gt;Ein lokaler, oder entfernter authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler, oder entfernter authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0394</guid>
    </item>
  </channel>
</rss>
