
CVE-2026-2733 A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administrati… https://www.cve.org/CVERecord?id=CVE-2026-2733
Post summary
A vulnerability has been disclosed in Keycloak’s Docker v2 authentication endpoint that allows tokens to be issued even after a registry client has been removed from admin permissions.
