Red hat build of keycloak 26.6.4
This hub aggregates every CVE we track for Red hat build of keycloak 26.6.4, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
7
0
0
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Red hat build of keycloak 26.6.4.
- CVE-2026-11800Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion8.1
- CVE-2026-9083Keycloak: keycloak: information disclosure through arbitrary filesystem path probing4.9
- CVE-2026-9799Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass4.6
- CVE-2026-9705Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token6.5
- CVE-2026-9086Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass7.3
- CVE-2026-9099Keycloak: group-admin escalation to realm-admin7.7
- CVE-2026-9800Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison8.1
- CVE-2026-9795Keycloak: keycloak: privilege escalation via improper scope mapping enforcement7.3
Product normalization is registry-driven with AI assist and human review. How it works