Back

HIGH

Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw

Published Apr 2, 2026

Description

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Red Hat statement

This is an IMPORTANT vulnerability in Keycloak. An unauthenticated attacker can exploit a lack of type and namespace isolation in Keycloak's SingleUseObjectProvider to forge authorization codes and obtain admin-capable access tokens. This could lead to unauthorized administrative access within affected Keycloak deployments.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 2, 2026
Updated Jul 15, 2026
Reserved Mar 16, 2026
CISA Vulnrichment
Updated Apr 2, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Apr 2, 2026
ENISA EUVD
Assigner redhat
Published Apr 2, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-18208 GHSA-HJ93-H7PG-FH6V