Description
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- RedHat / build_of_keycloak
- RedHat / build_of_keycloak26.2 – 26.2
- RedHat / build_of_keycloak26.2.15 – 26.2.15
- RedHat / build_of_keycloak26.4 – 26.4
- RedHat / build_of_keycloak26.4.11 – 26.4.11
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:6475
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:6476
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:6477
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:6478
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-4282
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2448061
Updated 8m ago · 8 sources