HIGH 7.4 Maven

Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw

GHSA-hj93-h7pg-fh6v · CVE-2026-4282

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

Ready to move

Start Securing

Free, no credit card | First findings in minutes