Launch Week Day 1: Announcing Security Design Review
HIGH 7.4 Maven

Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw

GHSA-hj93-h7pg-fh6v · CVE-2026-4282

Published · Modified

Description

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

Ready to move

Start Securing

Free, no credit card | First findings in minutes