CVE-2026-4366Disclosure(redhat / build_of_keycloak)

LOWCVSS 5.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak
  • jboss_enterprise_application_platform
  • jboss_enterprise_application_platform_expansion_pack
  • single_sign-on

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
build_of_keycloakjboss_enterprise_application_platformjboss_enterprise_application_platform_expansion_packsingle_sign-on

3 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-18: 3Technical Details · 2026-03-18: 203-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4366 Server-Side Request Forgery Vulnerability in Keycloak Identity Management Platform https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4366

    Post summary

    CVE‑2026‑4366 is disclosed as a Server‑Side Request Forgery vulnerability affecting Keycloak; no PoC, exploit code, or patch details are provided.

    0000047
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4366 - Keycloak-services: blind server-side request forgery (ssrf) via http redirect handling in keycloak Intel Report: https://ift.tt/DjCFs70

    Post summary

    A new blind SSRF vulnerability (CVE‑2026‑4366) in Keycloak Services has been reported with technical details, but there is no evidence of a PoC, exploit code, active exploitation, or patch information.

    0000044
    335 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4366 📊 Severity: 5.8 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4366 #CVE-2026-4366 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/hfdb5H4USh

    Post summary

    The tweet announces CVE-2026-4366, noting its medium severity, but offers no further technical details or actionable information.

    0000043
    104 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---
Appredhatjboss_enterprise_application_platform8.0.0--
Appredhatjboss_enterprise_application_platform_expansion_pack---
Appredhatsingle_sign-on7.0--

Explore more