CVE-2026-3872: Red Hat Build Of Keycloak

High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

Affected products

  • Red Hat Build Of Keycloak: affected versions not specified; version 26.2 only; version 26.2.15 only; version 26.4 only; version 26.4.11 only

Published 2026-04-02. Last modified 2026-07-15.