CVE Vulnerabilities

CVE-2026-4282

Improper Isolation or Compartmentalization

Published: Apr 02, 2026 | Modified: Jun 30, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

NameVendorStart VersionEnd Version
Build_of_keycloakRedhat- (including)- (including)
Build_of_keycloakRedhat26.2 (including)26.2 (including)
Build_of_keycloakRedhat26.2.15 (including)26.2.15 (including)
Build_of_keycloakRedhat26.4 (including)26.4 (including)
Build_of_keycloakRedhat26.4.11 (including)26.4.11 (including)
Red Hat build of Keycloak 26.2RedHatrhbk/keycloak-operator-bundle:26.2.15-1*
Red Hat build of Keycloak 26.2RedHatrhbk/keycloak-rhel9:26.2-18*
Red Hat build of Keycloak 26.2RedHatrhbk/keycloak-rhel9-operator:26.2-18*
Red Hat build of Keycloak 26.2.15RedHatrhbk/keycloak-rhel9*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-operator-bundle:26.4.11-1*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9:26.4-14*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9-operator:26.4-14*
Red Hat build of Keycloak 26.4.11RedHatrhbk/keycloak-rhel9*

Potential Mitigations

References