CVE-2026-4282Disclosure(redhat / build_of_keycloak)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-653

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
build_of_keycloak

5 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-02: 1Mentions · 2026-06-24: 1PoC Mentioned / Linked · 2026-06-24: 1Technical Details · 2026-04-02: 1Technical Details · 2026-06-24: 104-0206-24
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-06-241
PoC1
Full discourse2 posts
  • kmkz@kmkz_security
    PoC

    #Keycloak pwnage, all public. 1: CVE-2026-4282 forges admin tokens unauth 2: view-clients leaks every client secret, all versions, open #49220 (PoC: https://tinyurl.com/kmkz2) 3: restart revives rotated refresh tokens, CVE-2026-9802 Not every vuln has a CVE https://github.com/keycloak/keycloak/issues/

    Post summary

    Post lists multiple Keycloak CVEs with technical details and a PoC link, but does not mention active exploitation or patches.

    340119516024.1K
    19.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4282 A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthentic… https://www.cve.org/CVERecord?id=CVE-2026-4282

    Post summary

    The passage discloses a flaw (CVE-2026-4282) in Keycloak’s SingleUseObjectProvider, citing improper type and namespace isolation that could enable authentication bypass.

    00010146
    56.9K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---
Appredhatbuild_of_keycloak26.2--
Appredhatbuild_of_keycloak26.2.15--
Appredhatbuild_of_keycloak26.4--
Appredhatbuild_of_keycloak26.4.11--

Explore more