CVE-2026-4325: Red Hat Build Of Keycloak
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise.
Affected products
- Red Hat Build Of Keycloak: affected versions not specified; version 26.2 only; version 26.2.15 only; version 26.4 only; version 26.4.11 only
Published 2026-04-02. Last modified 2026-06-17.