Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-18201

Опубликовано: 29 июл. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

EPSS

Процентиль: 21%
0.00285
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.5
redhat
20 дней назад

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

CVSS3: 5.5
debian
19 дней назад

Keycloak provides a way to manage identity providers and organizations ...

CVSS3: 5.5
github
19 дней назад

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

EPSS

Процентиль: 21%
0.00285
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-862