Description
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
Problem types
Improper Isolation or Compartmentalization
Product status
26.2.15-1 (rpm) before *
26.2-18 (rpm) before *
26.2-18 (rpm) before *
26.4.11-1 (rpm) before *
26.4-14 (rpm) before *
26.4-14 (rpm) before *
Timeline
| 2026-03-16: | Reported to Red Hat. |
| 2026-04-02: | Made public. |
Credits
Red Hat would like to thank chungkn (OneMount Group) for reporting this issue.
References
access.redhat.com/errata/RHSA-2026:6475 (RHSA-2026:6475)
access.redhat.com/errata/RHSA-2026:6476 (RHSA-2026:6476)
access.redhat.com/errata/RHSA-2026:6477 (RHSA-2026:6477)
access.redhat.com/errata/RHSA-2026:6478 (RHSA-2026:6478)
access.redhat.com/security/cve/CVE-2026-4282
bugzilla.redhat.com/show_bug.cgi?id=2448061 (RHBZ#2448061)