LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-4366

redhat · build of keycloak

Published
CVSS5.8
Severitymedium
WeaknessCWE-918
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Description

A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4366

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-4366.