Keycloak Alert: Multiple Vulnerabilities Allow Remote Code Execution

Multiple security vulnerabilities have been identified in the Keycloak identity and access management platform. According to the CERT‑FR alert, several of these flaws allow an attacker to execute arbitrary code remotely, elevate privileges, or compromise the integrity and confidentiality of data. The issues also enable policy bypass and remote cross‑site scripting attacks. Affected releases include all Keycloak 26.0.x versions prior to 26.0.10 and all 26.6.x versions prior to 26.6.4. The alert references eight GitHub security advisories (GHSA‑2qxf‑v3g6‑73v9, GHSA‑32h4‑44jj‑c5vx, etc.) and several CVE identifiers (CVE‑2026‑11800, CVE‑2026‑9083, etc.). Organizations running vulnerable versions are advised to apply the vendor‑issued patches as detailed in the advisories. The alert lists six risk categories: data integrity loss, confidentiality breach, security policy bypass, remote code execution, remote cross‑site scripting, and privilege escalation. The CERT‑FR recommends consulting the vendor’s security advisories for patch information. Keycloak developers have published patches for the affected releases; administrators should update promptly to ensure system security.

Summary of content from

source

Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.


Posted