CVE-2026-4282
Java vulnerability analysis and mitigation

Overview

CVE-2026-4282 is a privilege escalation vulnerability in Keycloak caused by improper isolation in the SingleUseObjectProvider component, allowing unauthenticated attackers to forge authorization codes and create admin-capable access tokens. It was reported on March 16, 2026, and publicly disclosed on April 2, 2026. Affected versions include org.keycloak:keycloak-services prior to 26.5.7 (upstream), and Red Hat Build of Keycloak versions prior to 26.2.15 (26.2 branch) and prior to 26.4.11 (26.4 branch). It carries a CVSS v3.1 base score of 7.4 (High) (Red Hat CVE, Github Advisory).

Technical details

The root cause is classified as CWE-653 (Improper Isolation or Compartmentalization). Keycloak's SingleUseObjectProvider is a global flat key-value store shared across multiple internal features without type or namespace separation, meaning entries created for one purpose (e.g., action tokens) can be read or manipulated in the context of another (e.g., authorization codes). An unauthenticated network attacker with sufficient knowledge of the key structure can exploit this design flaw to inject or forge authorization codes, which Keycloak then processes as legitimate, ultimately allowing the minting of access tokens with administrative privileges. The attack complexity is rated High, reflecting the need for specific knowledge of the key-value store's internal structure (Github Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows an unauthenticated attacker to forge authorization codes and obtain admin-capable access tokens, resulting in full privilege escalation within Keycloak. This grants the attacker administrative control over Keycloak itself and any applications relying on it for authentication and authorization, enabling unauthorized access to sensitive user data, configuration changes, and potential lateral movement into dependent systems. Confidentiality and integrity impacts are both rated High; availability is not directly affected (Red Hat CVE, Github Advisory).

Indicators of compromise

  • Logs: Keycloak audit/event logs showing unexpected admin-level token issuance or authorization code exchanges not correlated with legitimate user authentication sessions; repeated or anomalous token exchange requests from unknown or unauthenticated sources.
  • Logs: Keycloak server logs showing unusual access to SingleUseObjectProvider entries, particularly key lookups or writes that cross feature boundaries (e.g., action token keys used in authorization code flows).
  • Network: Unexpected administrative API calls (e.g., to /admin/realms/) originating from sessions backed by tokens with no corresponding legitimate login event.
  • Process/Behavior: New admin users, realm configurations, or client registrations created without corresponding administrator activity in audit logs.

Mitigation and workarounds

Red Hat has released patched versions addressing this vulnerability: upgrade to Red Hat Build of Keycloak 26.2.15 (errata RHSA-2026:6475 for packages, RHSA-2026:6476 for OpenShift images) or 26.4.11 (errata RHSA-2026:6477 and RHSA-2026:6478). For upstream Keycloak users, upgrade to version 26.5.7 or later. No configuration-based workaround has been published; patching is the recommended remediation. Organizations should also review Keycloak access logs for signs of unauthorized administrative token creation as a precautionary measure (RHSA-2026:6475, RHSA-2026:6476, Github Advisory).

Community reactions

Red Hat classified this advisory as Important severity and released coordinated errata across multiple product streams on April 2, 2026 (RHSA-2026:6475). The Keycloak project published a release announcement for version 26.5.7 addressing this and related issues. Social media activity was limited to automated CVE tracking accounts (e.g., Bluesky CVE feeds), with no notable independent researcher commentary or significant community discussion identified at the time of disclosure.

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management