
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4282 is a privilege escalation vulnerability in Keycloak caused by improper isolation in the SingleUseObjectProvider component, allowing unauthenticated attackers to forge authorization codes and create admin-capable access tokens. It was reported on March 16, 2026, and publicly disclosed on April 2, 2026. Affected versions include org.keycloak:keycloak-services prior to 26.5.7 (upstream), and Red Hat Build of Keycloak versions prior to 26.2.15 (26.2 branch) and prior to 26.4.11 (26.4 branch). It carries a CVSS v3.1 base score of 7.4 (High) (Red Hat CVE, Github Advisory).
The root cause is classified as CWE-653 (Improper Isolation or Compartmentalization). Keycloak's SingleUseObjectProvider is a global flat key-value store shared across multiple internal features without type or namespace separation, meaning entries created for one purpose (e.g., action tokens) can be read or manipulated in the context of another (e.g., authorization codes). An unauthenticated network attacker with sufficient knowledge of the key structure can exploit this design flaw to inject or forge authorization codes, which Keycloak then processes as legitimate, ultimately allowing the minting of access tokens with administrative privileges. The attack complexity is rated High, reflecting the need for specific knowledge of the key-value store's internal structure (Github Advisory, Red Hat Bugzilla).
Successful exploitation allows an unauthenticated attacker to forge authorization codes and obtain admin-capable access tokens, resulting in full privilege escalation within Keycloak. This grants the attacker administrative control over Keycloak itself and any applications relying on it for authentication and authorization, enabling unauthorized access to sensitive user data, configuration changes, and potential lateral movement into dependent systems. Confidentiality and integrity impacts are both rated High; availability is not directly affected (Red Hat CVE, Github Advisory).
SingleUseObjectProvider entries, particularly key lookups or writes that cross feature boundaries (e.g., action token keys used in authorization code flows)./admin/realms/) originating from sessions backed by tokens with no corresponding legitimate login event.Red Hat has released patched versions addressing this vulnerability: upgrade to Red Hat Build of Keycloak 26.2.15 (errata RHSA-2026:6475 for packages, RHSA-2026:6476 for OpenShift images) or 26.4.11 (errata RHSA-2026:6477 and RHSA-2026:6478). For upstream Keycloak users, upgrade to version 26.5.7 or later. No configuration-based workaround has been published; patching is the recommended remediation. Organizations should also review Keycloak access logs for signs of unauthorized administrative token creation as a precautionary measure (RHSA-2026:6475, RHSA-2026:6476, Github Advisory).
Red Hat classified this advisory as Important severity and released coordinated errata across multiple product streams on April 2, 2026 (RHSA-2026:6475). The Keycloak project published a release announcement for version 26.5.7 addressing this and related issues. Social media activity was limited to automated CVE tracking accounts (e.g., Bluesky CVE feeds), with no notable independent researcher commentary or significant community discussion identified at the time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."