A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:19596 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:19597 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-4630 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2450245 | Vendor Advisory |
Configurations
History
03 Jun 2026, 19:53
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:* | |
| References | () https://access.redhat.com/errata/RHSA-2026:19596 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19597 - Vendor Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-4630 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2450245 - Vendor Advisory | |
| First Time |
Redhat
Redhat build Of Keycloak |
20 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 12:16
Updated : 2026-06-03 19:53
NVD link : CVE-2026-4630
Mitre link : CVE-2026-4630
CVE.ORG link : CVE-2026-4630
JSON object : View
Products Affected
redhat
- build_of_keycloak
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
