CVE-2026-7571

7.1

Red Hat · Red Hat build of Keycloak

A vulnerability in the Red Hat build of Keycloak allows for the external control of assumed-immutable web parameters, potentially leading to unauthorized configuration changes or security bypasses.

Executive summary

An external control of immutable web parameters in Red Hat build of Keycloak (v26.4/26.4.12) allows authenticated users to manipulate system parameters, impacting overall security posture.

Vulnerability

The vulnerability involves the external control of assumed-immutable web parameters (CWE-472). An authenticated attacker can influence these parameters, which were intended to be immutable, potentially leading to an escalation of privileges or security configuration bypass.

Business impact

As an identity and access management (IAM) solution, Keycloak is a high-value target. A CVSS score of 7.1 highlights the severity of this flaw, which could allow an authenticated user to alter authentication flows or security policies. The potential for unauthorized access to integrated downstream applications makes this a high-priority remediation item.

Remediation

Immediate Action: Update the Red Hat build of Keycloak to version 26.4.12-1 or 26.4-17, depending on the specific deployment branch, as specified in the vendor advisory.

Proactive Monitoring: Audit Keycloak administrative logs for unauthorized changes to security realms or authentication policies that deviate from established baselines.

Compensating Controls: Limit access to the Keycloak administrative console to trusted IP ranges and enforce Multi-Factor Authentication (MFA) for all administrative accounts to minimize the risk of malicious authenticated activity.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Identity providers serve as the backbone of organizational security; therefore, any vulnerability affecting Keycloak must be treated as a priority. Administrators should apply the provided Red Hat security updates immediately to ensure the integrity of the authentication and authorization services.

More Red Hat CVEs