
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4366 is a Blind Server-Side Request Forgery (SSRF) vulnerability in Keycloak, an open-source identity and access management solution, caused by improper handling of HTTP redirects during client configuration processing. Disclosed on March 18, 2026, it affects Red Hat Build of Keycloak, Red Hat Single Sign-On 7.0, JBoss Enterprise Application Platform 8.0.0, and JBoss Enterprise Application Platform Expansion Pack. The vulnerability carries a CVSS v3.1 base score of 5.8 (Medium) (Red Hat CVE, Red Hat Bugzilla).
The root cause is classified as CWE-918 (Server-Side Request Forgery), arising because Keycloak follows HTTP redirect responses (e.g., HTTP 302) without validating the final destination URL during client configuration processing. An attacker can supply a crafted sector_identifier_uri that initially appears to match allowed patterns but redirects to internal resources such as cloud metadata endpoints (e.g., 169.254.169.254). This causes Keycloak to issue unintended requests from its own network context, enabling blind SSRF — the attacker does not receive direct response content but can infer internal service availability. Exploitation requires no authentication or user interaction and is reachable over the network (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation allows unauthenticated remote attackers to cause the Keycloak server to make unintended HTTP requests to internal or restricted resources, including cloud instance metadata endpoints (e.g., AWS IMDSv1 at 169.254.169.254). This can result in information disclosure — including exposure of cloud credentials, API tokens, or configuration data stored in metadata services — and enables attackers to map internal network infrastructure. The scope is marked as "Changed" in the CVSS vector, indicating impact extends beyond the vulnerable component itself (Red Hat CVE, Red Hat Bugzilla).
sector_identifier_uri parameter that points to an attacker-controlled server initially serving a valid JSON response, but configured to issue an HTTP 302 redirect to an internal target (e.g., http://169.254.169.254/latest/meta-data/).169.254.169.254, RFC 1918 addresses) or unexpected external hosts; unusual DNS lookups originating from the Keycloak host.sector_identifier_uri values pointing to external or internal redirect chains; HTTP client errors or timeouts related to internal endpoint access attempts.sector_identifier_uri values from the same source IP, suggesting enumeration activity; unexpected 302 redirect chains logged in Keycloak's HTTP client trace logs.Red Hat has released patches for all affected products: Red Hat Build of Keycloak, Red Hat Single Sign-On 7.0, JBoss Enterprise Application Platform 8.0.0, and JBoss Enterprise Application Platform Expansion Pack. The upstream Keycloak project addressed this in version 26.6.1/26.6.2 (released April 2026) (Keycloak Release). As interim workarounds, administrators should implement network segmentation to prevent the Keycloak server from making outbound requests to internal services and cloud metadata endpoints, disable dynamic client registration if not required, and monitor for suspicious HTTP redirect patterns in client configuration requests (Red Hat CVE, Red Hat Bugzilla).
Coverage of CVE-2026-4366 has been limited to vulnerability tracking platforms and automated security feeds, with no notable researcher commentary or significant social media discussion identified. The Keycloak project acknowledged the fix in its April 2026 release notes (Keycloak Release). The vulnerability was also catalogued by ENISA under EUVD-2026-12762 and tracked by INCIBE-CERT.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."