news.mlab.sh
Back to the feed
vulnerability

Vulnérabilité dans KeyCloak (17 septembre 2026)

HighCVSS 7.4
Summary

A vulnerability in Keycloak versions 26.7.x allows attackers to bypass security policies. This could lead to unauthorized access and potential data breaches. Users are advised to apply the latest security updates immediately.

A security vulnerability has been identified within Keycloak. This flaw enables an attacker to circumvent existing security policies, potentially gaining unauthorized access to the system. The vulnerability is present in Keycloak versions 26.7.x, prior to version 26.7.4. The advisory from CERT-FR highlights the need for immediate action to mitigate the risk. Users should consult the provided security bulletin for detailed instructions on how to apply the necessary patches and updates. The bulletin references CVE-2026-90997, a common identifier for this vulnerability.

Read the full article at CERT-FR