Beveiligingsadvies

CVE-2026-4282

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-02 12:44:52
Laatst bijgewerkt 2026-07-15 00:56:46
Toegewezen door redhat
CVSS-score 7.4
Status PUBLISHED

Beschrijving

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.