PT-2026-29729 · Red Hat · Keycloak

·

CVE-2026-4282

·

Published

2026-04-02

·

Updated

2026-08-25

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat build of Keycloak version 26.2
Description A flaw exists in the SingleUseObjectProvider, which serves as a global key-value store. This component lacks proper type and namespace isolation, allowing an unauthenticated attacker to forge authorization codes. This can lead to the creation of access tokens with administrative capabilities, resulting in privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-4282
CVE-2026-4282
ECHO-DC8F-BECE-24E2
GHSA-HJ93-H7PG-FH6V

Affected Products

Keycloak