CVE-2025-14083: Red Hat Build Of Keycloak 26.4
Low severity, CVSS 2.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.
Affected products
- Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.11-1 (fixed in 26.4.11-1); before 26.4-14 (fixed in 26.4-14)
- Red Hat Red Hat Build Of Keycloak 26.4.11
Published 2026-01-21. Last modified 2026-06-17.