ZeroHour

CVE-2026-3872

CVSS 3.1
7.3 high
EPSS
<1%p37
Published
()
Modified
Description

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

Vendors
redhat
Products
build of keycloak
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.