CVE Tools

Red Hat Build of Keycloak

122 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Build of Keycloak, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Build of Keycloak CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Build of Keycloak CVEs per month
MonthCVEs
2024-104
2024-115
2024-124
2025-014
2025-022
2025-032
2025-042
2025-050
2025-061
2025-070
2025-081
2025-090
2025-100
2025-110
2025-121
2026-012
2026-023
2026-035
2026-042
2026-051
2026-062
2026-0712
2026-084
2026-0939

Severity

How the 122 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High3428%
  • Medium7461%
  • Low1411%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Build of Keycloak.

  1. CVE-2026-96448Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation6.6
  2. CVE-2026-97846Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding6.8
  3. CVE-2026-97311Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization4.3
  4. CVE-2026-97177Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission6.6
  5. CVE-2026-97176Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator4.2
  6. CVE-2026-96445Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers6.8
  7. CVE-2026-96446Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path4.2
  8. CVE-2026-95503Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabled6.8
  9. CVE-2026-94218Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpoint3.1
  10. CVE-2026-94217Keycloak-services: keycloak-services: uma scope merge across resource owners via resource name collision3.5
  11. CVE-2026-94215Keycloak-services: keycloak-services: cross-realm client read/write via request-level cache missing realm ownership check5.5
  12. CVE-2026-94213Keycloak-services: keycloak-services: authorization services policy evaluation endpoint leaks user identity4.9
  13. CVE-2026-94001Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-password permission6.5
  14. CVE-2026-94000Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership6.6
  15. CVE-2026-93999Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled audience clients4.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store