CVE-2026-4628Disclosure(redhat / build_of_keycloak)

LOWCVSS 4.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT operations to the resource_set endpoint. This issue enables unauthorized modification of protected resources, impacting data integrity.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
build_of_keycloak

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-23: 4Technical Details · 2026-03-23: 303-23
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4628 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4628 #CVE-2026-4628 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/waAjbAiZVp

    Post summary

    A brief announcement of CVE-2026-4628 with a medium risk rating and a link to the NVD entry, but no further technical, exploit, or mitigation details.

    0000028
    111 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4628 - Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control Intel Report: https://ift.tt/73rPKWc

    Post summary

    The alert announces CVE-2026-4628, a Keycloak access‑control flaw allowing unauthorized resource modification, and links to an Intel report.

    0000034
    289 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4628 Keycloak UMA Resource Management Bypass Vulnerability in Access Control Mechanism https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4628

    Post summary

    The text announces CVE‑2026‑4628 as a resource‑management bypass in Keycloak’s access control, without providing PoC, exploit, or patch details.

    0000055
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4628 - Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control Intel Report: https://ift.tt/83yblV7

    Post summary

    The alert announces Keycloak CVE‑2026‑4628, describing it as an unauthorized resource modification vulnerability caused by improper access control; no PoC, exploit, or patch details are provided.

    0000023
    290 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more