| keycloak-services: keycloak-services: Client access-type policy condition bypass during client update CVE-2026-18573 | Severity medium |
| keycloak-services: keycloak-services: UMA claim token can override authorization time-policy evaluation attributes CVE-2026-18572 | Severity medium |
| keycloak-services: keycloak-services: FGAP V2 group assignment bypass during user creation CVE-2026-18571 | Severity high |
| keycloak-services: keycloak-services: Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed CVE-2026-18570 | Severity medium |
| keycloak-services: keycloak-services: Client not-before revocation ignored when realm not-before is older but nonzero CVE-2026-18218 | Severity medium |
| keycloak-services: keycloak-services: Microsoft external access-token exchange bypasses configured tenant CVE-2026-18215 | Severity high |
| keycloak-services: keycloak-services: Google external access-token exchange bypasses hosted-domain restriction CVE-2026-18214 | Severity high |
| keycloak-services: keycloak-services: OIDC redirect_uri fragment bypass in HTTP parameter pollution check CVE-2026-18209 | Severity medium |
| keycloak-services: keycloak-services: Generic identity-provider creation can bind brokers to organizations without manage-organizations CVE-2026-18201 | Severity medium |
| keycloak-services: keycloak-services: Information disclosure via role-users endpoint bypasses per-user view filter CVE-2026-17059 | Severity medium |
| keycloak-services: keycloak-services: Realm default-group reads disclose hidden groups under FGAP v2 CVE-2026-16108 | Severity medium |
| keycloak-services: keycloak-services: Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged… CVE-2026-16106 | Severity medium |
| keycloak-services: keycloak-services: Missing per-role authorization on RoleContainerResource composite endpoints CVE-2026-16105 | Severity medium |
| keycloak-services: keycloak-services: Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins CVE-2026-16104 | Severity medium |
| keycloak-services: keycloak-services: Required signed-JWT assertion policy can be bypassed with unsigned assertion headers CVE-2026-16093 | Severity medium |
| keycloak-services: keycloak-services: Authorization codes can be retargeted to another client session CVE-2026-16089 | Severity medium |
| keycloak-services: keycloak-services: Organization invitation link exposure allows unauthorized member creation CVE-2026-16072 | Severity medium |
| keycloak-services: keycloak-services: Group hierarchy search discloses hidden parent groups under FGAP v2 CVE-2026-15945 | Severity medium |
| keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison CVE-2026-9800 | Severity high |
| keycloak: Keycloak: Privilege escalation via Time-of-Check to Time-of-Use (TOCTOU) vulnerability CVE-2026-9796 | Severity medium |
| org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover CVE-2026-7507 | Severity high |
| keycloak: Keycloak: Denial of Service via specially crafted SAML input CVE-2026-7307 | Severity high |
| keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters CVE-2026-4634 | Severity high |
| org.keycloak/keycloak-services: Improper Enforcement of Disabled Identity Provider in IdentityBrokerService (Authentication Bypass) CVE-2026-3009 | Severity high |
| keycloak: Keycloak: Denial of Service due to excessive SAMLRequest decompression CVE-2026-2575 | Severity medium |
| keycloak-services: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions CVE-2026-2092 | Severity high |
| org.keycloak.authentication: Two factor authentication bypass CVE-2025-3910 | Severity medium |
| A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests… CVE-2024-7885 | Severity high |