CVE-2026-4366
Last modified
CVE-2026-4366 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | All versions |
| Redhat | Jboss Enterprise Application Platform | 8.0.0 |
| Redhat | Jboss Enterprise Application Platform Expansion Pack | All versions |
| Redhat | Single Sign-On | 7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-4366?
How severe is CVE-2026-4366?
How do I fix CVE-2026-4366?
Are you affected by CVE-2026-4366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
