CVE Vulnerabilities

CVE-2026-4325

Improper Isolation or Compartmentalization

Published: Apr 02, 2026 | Modified: Apr 16, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise.

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

NameVendorStart VersionEnd Version
Build_of_keycloakRedhat- (including)- (including)
Build_of_keycloakRedhat26.2 (including)26.2 (including)
Build_of_keycloakRedhat26.2.15 (including)26.2.15 (including)
Build_of_keycloakRedhat26.4 (including)26.4 (including)
Build_of_keycloakRedhat26.4.11 (including)26.4.11 (including)
Red Hat build of Keycloak 26.2RedHatrhbk/keycloak-operator-bundle:26.2.15-1*
Red Hat build of Keycloak 26.2RedHatrhbk/keycloak-rhel9:26.2-18*
Red Hat build of Keycloak 26.2RedHatrhbk/keycloak-rhel9-operator:26.2-18*
Red Hat build of Keycloak 26.2.15RedHatrhbk/keycloak-rhel9*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-operator-bundle:26.4.11-1*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9:26.4-14*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9-operator:26.4-14*
Red Hat build of Keycloak 26.4.11RedHatrhbk/keycloak-rhel9*

Potential Mitigations

References