CVE-2026-4636: Red Hat Build Of Keycloak
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.
Affected products
- Red Hat Build Of Keycloak: affected versions not specified; version 26.2 only; version 26.2.15 only; version 26.4 only; version 26.4.11 only
Published 2026-04-02. Last modified 2026-07-15.