๐Ÿ” CVE Alert

CVE-2026-4630

MEDIUM 6.8

Keycloak: keycloak: unauthorized resource access and data modification via insecure direct object reference

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
8th

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.

CWE CWE-639
Vendor red hat
Product red hat build of keycloak 26.4
Published May 19, 2026
Last Updated May 20, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak 26.4

Be the first to know when new medium vulnerabilities affecting red hat red hat build of keycloak 26.4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4.12
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:19596 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:19597 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-4630 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2450245