Red Hat build of Keycloak 26.6 vulnerability

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

Published 29 Jul 2026Updated 16 Sep 20264 sources
CVSS 5.5

Source timeline

CVE record published by NVDView source ↗