Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18201

Опубликовано: 28 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires high-privileged administrative access (manage-identity-providers) to exploit. Successful exploitation allows an attacker to associate identity brokers with organizations they are not authorized to manage, potentially influencing login flows. The vulnerability's root cause is a missing authorization check in the generic identity-provider creation REST endpoint.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesAffected
Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Affected
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2508290keycloak-services: keycloak-services: Generic identity-provider creation can bind brokers to organizations without manage-organizations

EPSS

Процентиль: 21%
0.00285
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
19 дней назад

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

CVSS3: 5.5
debian
19 дней назад

Keycloak provides a way to manage identity providers and organizations ...

CVSS3: 5.5
github
19 дней назад

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

EPSS

Процентиль: 21%
0.00285
Низкий

5.5 Medium

CVSS3