<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:51:48 +0000</lastBuildDate>
    <item>
      <title>BIT-keycloak-2026-4630 — Keycloak: keycloak: unauthorized resource access and data modification via insecure direct object reference</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-4630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource&amp;#39;s unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource&amp;#39;s unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-4630</guid>
    </item>
    <item>
      <title>EUVD-2026-319727</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319727</link>
      <description>EUVD-2026-319727</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319727</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4630</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4630</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource&amp;#39;s unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource&amp;#39;s unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4630</guid>
    </item>
    <item>
      <title>GHSA-c739-f6xw-6pv2 — Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c739-f6xw-6pv2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;Keycloak&amp;#39;s Authorization Services feature exposes a User-Managed Access Protection API that include an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource&amp;#39;s unique identifier (UUID) belonging to another Resource Server within the same realm, an authenticated client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;Keycloak&amp;#39;s Authorization Services feature exposes a User-Managed Access Protection API that include an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource&amp;#39;s unique identifier (UUID) belonging to another Resource Server within the same realm, an authenticated client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c739-f6xw-6pv2</guid>
    </item>
    <item>
      <title>RHSA-2026:19596 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.12 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:19596</link>
      <description>&lt;p&gt;keycloak-services: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling in Keycloak keycloak: Keycloak: Unauthorized resource access and data modification via Insecure Direct Object Reference keycloak: Keycloak: Denial of Service via specially crafted SAML input org.keycloak/keycloak-services: Open redirect when using wildcard valid redirect URIs in Keycloak org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak-services: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling in Keycloak keycloak: Keycloak: Unauthorized resource access and data modification via Insecure Direct Object Reference keycloak: Keycloak: Denial of Service via specially crafted SAML input org.keycloak/keycloak-services: Open redirect when using wildcard valid redirect URIs in Keycloak org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:19596</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1612 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Sicherheitsvorkehrungen zu umgehen und einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Sicherheitsvorkehrungen zu umgehen und einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612</guid>
    </item>
  </channel>
</rss>
