
#Keycloak pwnage, all public. 1: CVE-2026-4282 forges admin tokens unauth 2: view-clients leaks every client secret, all versions, open #49220 (PoC: https://tinyurl.com/kmkz2) 3: restart revives rotated refresh tokens, CVE-2026-9802 Not every vuln has a CVE https://github.com/keycloak/keycloak/issues/
Post summary
The tweet lists three Keycloak CVEs, provides a PoC link for one, and summarizes the main impact of each vulnerability.
