CVE-2026-4282: Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
Other sources
Keycloak's SingleUseObjectProvider is a global flat key-value store used by multiple features without type or namespace isolation. This allows an unauthenticated attacker to forge authorization codes and mint admin-capable access tokens.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4282?
CVE-2026-4282 is classified as a critical vulnerability due to its potential for privilege escalation.
How do I fix CVE-2026-4282?
To resolve CVE-2026-4282, you should update Red Hat Keycloak to the latest patched version provided by Red Hat.
Who is affected by CVE-2026-4282?
CVE-2026-4282 affects multiple versions of Red Hat Keycloak, including versions 26.2, 26.2.15, 26.4, and 26.4.11.
What is the nature of the issue described in CVE-2026-4282?
CVE-2026-4282 involves a flaw in the SingleUseObjectProvider that allows unauthenticated attackers to perform privilege escalation through forged authorization codes.
Is there a workaround for CVE-2026-4282?
Currently, there is no official workaround available for CVE-2026-4282, and it is recommended to apply updates promptly.