RHSA-2026:6476HighCVSS 8.1

Red Hat Security Advisory: Red Hat build of Keycloak 26.2.15 Images Update

Published
April 2, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-3872 — keycloak: Keycloak: Information disclosure due to redirect_uri validation bypass CVE-2026-4282 — keycloak: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw CVE-2026-4325 — keycloak: Keycloak: Replay of action tokens via improper handling of single-use entries CVE-2026-4634 — keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters CVE-2026-4636 — keycloak: Keycloak: UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.

🎯 Affected products10

  • Red Hat build of Keycloak 26.2
  • rhbk/keycloak-operator-bundle@sha256:d80f27078e17321d4b194820a9c325c47b8cc3e431ac37c84a6c5b2b52b009e6_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:1880e406eab1303dd1faa08694ff2cb33901e1e69272a2f9cdf5f5af6941bd84_arm64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:31378e237970d0c5c483ec2dd3de6a39adfb7cdfe13c5d106be39088859271e6_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:47fa46896eda2f3c51657f6bc9a024d63f3d306f4726ead3fa46ef5796696e07_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:6c0c1d05bb893e1d598ffc5e953f1287d36e78f6b1938c430e0bc19e22343ae4_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:10b97dd8e38ce50457a121e53d53472877cc3aa185e7c4b23da191c00e914af2_arm64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:4065d584a57daa2aa2259afa19844f6308e2f6a252b08738c809002cc84aa606_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:4c4f3e098f715efc174a4a01803b7133ca7c2b744ea4b8151c7edcae608d9531_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:b3fe3f4c74e96a2daf735fe5e8df98b2fa6f023cfda0c7cd4915a83556e14efb_amd64 as a component of Red Hat build of Keycloak 26.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: To mitigate this vulnerability, avoid using wildcards in `redirect_uri` configurations within Keycloak. Restricting `redirect_uri` to explicit, fully qualified URIs prevents the bypass of validation logic. This configuration change may require a service restart or reload to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (3)