Improper Isolation or Compartmentalization in org.keycloak:keycloak-services
CVE-2026-4282
- org.keycloak:keycloak-services
Summary
A flaw was found in Keycloak Services prior to 26.5.7. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
- HIGH
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-653 - Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
References
Advisory Timeline
- Published