Red Hat Jboss Data Grid
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Red Hat Jboss Data Grid.
By the Year
In 2026 there have been 164 vulnerabilities in Red Hat Jboss Data Grid with an average score of 7.1 out of ten. Last year, in 2025 Jboss Data Grid had 10 security vulnerabilities published. That is, 154 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.62.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 164 | 7.11 |
| 2025 | 10 | 6.49 |
| 2024 | 17 | 6.51 |
| 2023 | 7 | 6.40 |
| 2022 | 1 | 8.80 |
| 2021 | 2 | 6.70 |
| 2020 | 9 | 7.44 |
| 2019 | 5 | 8.40 |
| 2018 | 1 | 8.80 |
It may take a day or so for new Jboss Data Grid vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Jboss Data Grid Security Vulnerabilities
Netty HTTP/1 Decoder Request Smuggling via Malformed Transfer-Encoding
CVE-2026-93562
6.5 - Medium
- September 18, 2026
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing security controls or accessing unauthorized resources.
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Netty netty-codec-http HTTP Smuggling via Chunk-Size Post-Digit Whitespace
CVE-2026-93574
6.5 - Medium
- September 18, 2026
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling. This allows an attacker to bypass security controls or access unauthorized resources in proxy/backend deployments.
HTTP Request Smuggling
Netty HTTP/2 Header Field Injection Vulnerability (CVE-2026-93579)
CVE-2026-93579
6.5 - Medium
- September 18, 2026
A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1.1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting. This could lead to unauthorized access, data manipulation, or other security bypasses.
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Netty Transfer-Encoding Field Split Bypass Enables Request Smuggling
CVE-2026-93573
6.5 - Medium
- September 18, 2026
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.
HTTP Request Smuggling
Red Hat: HTTP/2/3 EXT CONNECT Downgrade in Apache HTTPd
CVE-2026-93568
7.5 - High
- September 18, 2026
A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HTTP/1.1 CONNECT requests, leading to a loss of critical protocol and path information. This misinterpretation can allow attackers to bypass security policies, such as routing or authorization logic, in applications that rely on Netty for HTTP/2 or HTTP/3 communication, resulting in integrity loss.
Improper Input Validation
EAP Elytron Token-Realm OAuth2 Introspection URL Encoding Flaw
CVE-2026-85511
4.2 - Medium
- September 18, 2026
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
Authentication Bypass by Spoofing
Netty HTTP/1HTTP/2 Host Header Conflict Allows Unauthorized Access
CVE-2026-93569
8.2 - High
- September 18, 2026
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.
HTTP Request Smuggling
Netty HTTP/2 CONNECT Host Header Exploit Bypass Tunnel Allow-List
CVE-2026-93567
7.5 - High
- September 18, 2026
A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit this by supplying a different Host header, leading to a malformed HTTP/2 CONNECT request. This can bypass security controls such as tunnel allow-lists or egress policies, resulting in integrity loss.
Improper Input Validation
Netty HTTP Request Smuggling via Chunk-Size Line Bypass
CVE-2026-93566
6.5 - Medium
- September 18, 2026
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
WildFly Elytron ASN1 DERDecoder DoS via Excessive Memory Allocation
CVE-2026-10832
5.9 - Medium
- September 18, 2026
A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate excessive memory based on an inflated length value without proper validation, leading to Java Virtual Machine (JVM) memory exhaustion. This results in a remote Denial of Service (DoS) for services that process untrusted DER/ASN.1 input, including SASL (Simple Authentication and Security Layer) authentication mechanisms and X.500 certificate principal parsing paths.
Allocation of Resources Without Limits or Throttling
Netty RtspDecoder Method-Token Smuggling via RTSP Request
CVE-2026-93565
7.5 - High
- September 18, 2026
A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a specially crafted RTSP request, leading to method-token smuggling. This vulnerability allows an attacker to bypass method-based access controls and can also be used to launder malicious requests through Netty-based RTSP proxies, making them appear legitimate to backend systems.
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Netty WebSocketServerExtensionHandler DoS via HTTP/1.1 Pipelining Queue Overflow
CVE-2026-93558
7.5 - High
- September 18, 2026
A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server.
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Netty HpackEncoder DoS via oversized SETTINGS MAX_HEADER_TABLE_SIZE
CVE-2026-93492
5.3 - Medium
- September 18, 2026
A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory consumption, ultimately resulting in a Denial of Service (DoS).
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Netty HttpServerCodec DoS via HTTP/1.1 pipelining (before 4.2)
CVE-2026-93491
7.5 - High
- September 18, 2026
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
Allocation of Resources Without Limits or Throttling
Netty SpdySessionHandler Unbounded Streams DoS
CVE-2026-93488
7.5 - High
- September 18, 2026
A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service.
Allocation of Resources Without Limits or Throttling
Keycloak is an open-source identity and access management solution
CVE-2026-17526
7.2 - High
- September 16, 2026
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
AuthZ
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution
CVE-2026-18212
7.5 - High
- September 16, 2026
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated attacker can exploit this by sending repeated malformed SAML requests, leading to native memory exhaustion and a denial of service.
Memory Leak
Undertow WebSocket DoS via PerMessageDeflate Buffer Doubling
CVE-2026-5680
7.5 - High
- August 27, 2026
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
Allocation of Resources Without Limits or Throttling
WildFly Elytron Unicode Normalization Weakens Password Hashing
CVE-2026-19611
7.4 - High
- August 20, 2026
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
Improper Handling of Alternate Encoding
Predictable Hash Enables Account-Takeover via Keycloak Linking URL
CVE-2026-15571
7.3 - High
- August 18, 2026
A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.
Predictable from Observable State
Undertow ChunkReader State Overlap Allows Chunked Request Bypass
CVE-2026-14180
5.3 - Medium
- August 11, 2026
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls.
HTTP Request Smuggling
Undertow @ServerEndpoint WebSocket OOM DoS
CVE-2026-15565
7.5 - High
- August 11, 2026
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
Classic Buffer Overflow
Keycloak SAML Broker SSO Bypass via IdP Account Linking
CVE-2026-16442
7.4 - High
- August 05, 2026
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Origin Validation Error
Keycloak Prometheus Metric Label DoS via Memory Exhaustion
CVE-2026-16100
6.5 - Medium
- August 05, 2026
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.
Allocation of Resources Without Limits or Throttling
LDAP DN Boundary Bypass in Keycloak LDAP Storage Provider
CVE-2026-16071
5.4 - Medium
- August 05, 2026
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
LDAP Injection
Keycloak DCR Path Validation Flaw Enables Privilege Escalation
CVE-2026-16102
8.1 - High
- August 05, 2026
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
Keycloak PathMatcher URINormalization Auth Bypass
CVE-2026-15573
8.1 - High
- August 05, 2026
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
Red Hat Keycloak Services SAML Meta Import flaw: Signature Bypass
CVE-2026-16443
7.4 - High
- August 05, 2026
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Improper Verification of Cryptographic Signature
Keycloak Backchannel Logout Flaw: SIGOmitted OIDC Logout
CVE-2026-18569
3.7 - Low
- August 04, 2026
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.
Improper Verification of Cryptographic Signature
Keycloak Services Bypass of Client Policies via Confidential Client Update
CVE-2026-18573
6.5 - Medium
- August 02, 2026
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.
AuthZ
Keycloak Time Policy Bypass via Fake Time Claims
CVE-2026-18572
6.5 - Medium
- August 02, 2026
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
AuthZ
Keycloak: FGAP V2 Allows Unauthorized User Group Additions
CVE-2026-18571
6.6 - Medium
- August 02, 2026
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.
AuthZ
Red Hat Keycloak FullScopeDisabled Executor Bypass
CVE-2026-18570
5.4 - Medium
- August 02, 2026
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.
AuthZ
Keycloak keycloak-services OIDC Param Poll. Reroute Enables Session Fix
CVE-2026-18209
3.4 - Low
- July 31, 2026
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.
Improper Validation of Consistency within Input
Keycloak keycloak-services Hostname Validation Flaw Enables Unauth Client Mod
CVE-2026-18206
3.7 - Low
- July 31, 2026
A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.
Improper Input Validation
Keycloak Token Exchange Bypass: Domain Restriction Lapse
CVE-2026-18214
6.8 - Medium
- July 31, 2026
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.
AuthZ
Keycloak GPI Prefix Check IDOR Enables Admin Access
CVE-2026-18203
6.5 - Medium
- July 31, 2026
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.
AuthZ
Keycloak secure-client-uris flaw bypasses redirect URI security
CVE-2026-18211
4.2 - Medium
- July 31, 2026
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Due to an improper check that only looks at the start of a web address rather than properly verifying the host, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections.
Improper Input Validation
Unauthorized OIDC Introspection Exposure in Keycloak Services
CVE-2026-18208
6.5 - Medium
- July 31, 2026
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.
AuthZ
Keycloak RoleContainerResource Authorization Bypass in Admin REST API
CVE-2026-16105
4.9 - Medium
- July 31, 2026
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
Insecure Direct Object Reference / IDOR
Keycloak Token Exchange Bypass Ignoring Org Restriction
CVE-2026-18215
6.8 - Medium
- July 31, 2026
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.
authentification
Keycloak SAML Wildcard URL Injection (CVE-2026-18217)
CVE-2026-18217
3.4 - Low
- July 31, 2026
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
Improper Input Validation
TokenManager revocation bypass in Keycloak
CVE-2026-18218
4.2 - Medium
- July 31, 2026
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them.
AuthZ
Keycloak Admin API Allows Identity Provider Linking Without Org Admin Privileges
CVE-2026-18201
5.5 - Medium
- July 29, 2026
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.
AuthZ
Keycloak Client Policy Bypass via Group Name Match
CVE-2026-18207
6.5 - Medium
- July 29, 2026
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.
AuthZ
Keycloak role-users endpoint leaks user info due to missing admin permission
CVE-2026-17059
6.5 - Medium
- July 24, 2026
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.
Insecure Direct Object Reference / IDOR
Keycloak Admin REST API: View-Only Admins Can Leak Client Secrets
CVE-2026-17048
5.5 - Medium
- July 24, 2026
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Information Disclosure
KeycloakServices auth endpoint leaks recaptcha keys via config VIEW only
CVE-2026-16104
4.3 - Medium
- July 17, 2026
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.
Improper Removal of Sensitive Information Before Storage or Transfer
Brute-Force Token Redemption Loophole in Keycloak CIBA (keycloak-services)
CVE-2026-16103
4.3 - Medium
- July 17, 2026
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.
Authentication Bypass by Primary Weakness
Keycloak Admin API: RBAC Bypass Removing Composite Roles
CVE-2026-16106
4.9 - Medium
- July 17, 2026
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.
Insufficient Granularity of Access Control
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Red Hat Jboss Data Grid or by Red Hat? Click the Watch button to subscribe.