Where
-Infinity
0

Keycloak keycloak-servicesKeycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter

Risk 38
Severity
6.5
First published (updated )

Keycloak KeycloakA missing authorization filter flaw was found in Keycloaks role-users REST API endpoint. When an aut…

Risk 19
Severity
4
First published (updated )

Keycloak Keycloak Admin REST APIKeycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api

Risk 39
Severity
5.5
First published (updated )

Keycloak Keycloak Admin REST APIA sensitive information disclosure flaw was found in the Keycloak Admin REST API. The vulnerability …

Risk 19
Severity
4
First published (updated )

Keycloak Keycloak Admin REST APIKeycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak Keycloak Admin REST APIA flaw was found in the Keycloak Admin REST API when Fine-Grained Admin Permissions (FGAP) v2 is ena…

Risk 19
Severity
4
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles

Risk 30
Severity
4.9
First published (updated )

Keycloak KeycloakAn incorrect authorization flaw was found in the Keycloak admin REST API endpoints responsible for r…

Risk 19
Severity
4
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins

Risk 22
Severity
4.3
First published (updated )

Keycloak KeycloakAn Information Exposure vulnerability was found in the GET /admin/realms/{realm}/authentication/conf…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak KeycloakKeycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption

Risk 22
Severity
4.3
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers

Risk 34
Severity
5.4
First published (updated )

Keycloak keycloak-servicesA flaw was found in the Secure Client Registration executor within the keycloak-services component. …

Risk 19
Severity
4
First published (updated )

Keycloak organization management componentKeycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation

Risk 30
Severity
4.9
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change

Risk 39
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak KeycloakA vulnerability was identified in Keycloak's admin API where the secret masking boundary is bypassed…

Risk 19
Severity
4
First published (updated )

Keycloak OIDC broker componentA flaw was found in the OIDC broker component of Keycloak, which manages authentication through exte…

Risk 19
Severity
4
First published (updated )

Keycloak Keycloak Admin Services (keycloak: keycloak-services)Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter

Risk 22
Severity
4.3
First published (updated )

Keycloak KeycloakAn authorization bypass vulnerability exists in the GroupResource.getSubGroups() function of org.key…

Risk 19
Severity
4
First published (updated )

Keycloak ClientResource (admin services)Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak KeycloakA write-path authorization bypass vulnerability exists in the ClientResource.addDefaultClientScope()…

Risk 19
Severity
4
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission

Risk 22
Severity
4.3
First published (updated )

Keycloak Fine-Grained Admin Permissions v2 (FGAP v2)A flaw was found in Keycloak's Fine-Grained Admin Permissions v2 (FGAP v2) implementation. When FGAP…

Risk 19
Severity
4
First published (updated )

Keycloak keycloak-admin-uiKeycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions

Risk 22
Severity
4.3
First published (updated )

Keycloak Identity Provider (IdP) mapper componentKeycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper

Risk 49
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak Keycloak admin-ui-extKeycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak

Risk 30
Severity
4.9
First published (updated )

Keycloak Keycloak admin-ui-extAn authorization bypass vulnerability exists in the Keycloak admin-ui-ext bulk role-mapping-delete e…

Risk 19
Severity
4
First published (updated )

Keycloak KeycloakOrg.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion

Risk 60
Severity
8.1
First published (updated )

Keycloak KeycloakA JWT algorithm confusion vulnerability was found in Keycloak's JWT Authorization Grant flow . A fla…

Risk 33
Severity
7
First published (updated )

Keycloak KeycloakKeycloak: keycloak: denial of service via malformed ldap password policy response

Risk 22
Severity
4.9
EPSS
0.48%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203