CVE-2026-4366
JBoss EAP vulnerability analysis and mitigation

Overview

CVE-2026-4366 is a Blind Server-Side Request Forgery (SSRF) vulnerability in Keycloak, an open-source identity and access management solution, caused by improper handling of HTTP redirects during client configuration processing. Disclosed on March 18, 2026, it affects Red Hat Build of Keycloak, Red Hat Single Sign-On 7.0, JBoss Enterprise Application Platform 8.0.0, and JBoss Enterprise Application Platform Expansion Pack. The vulnerability carries a CVSS v3.1 base score of 5.8 (Medium) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), arising because Keycloak follows HTTP redirect responses (e.g., HTTP 302) without validating the final destination URL during client configuration processing. An attacker can supply a crafted sector_identifier_uri that initially appears to match allowed patterns but redirects to internal resources such as cloud metadata endpoints (e.g., 169.254.169.254). This causes Keycloak to issue unintended requests from its own network context, enabling blind SSRF — the attacker does not receive direct response content but can infer internal service availability. Exploitation requires no authentication or user interaction and is reachable over the network (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation allows unauthenticated remote attackers to cause the Keycloak server to make unintended HTTP requests to internal or restricted resources, including cloud instance metadata endpoints (e.g., AWS IMDSv1 at 169.254.169.254). This can result in information disclosure — including exposure of cloud credentials, API tokens, or configuration data stored in metadata services — and enables attackers to map internal network infrastructure. The scope is marked as "Changed" in the CVSS vector, indicating impact extends beyond the vulnerable component itself (Red Hat CVE, Red Hat Bugzilla).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Keycloak instances (or Red Hat SSO deployments) using tools like Shodan or Censys, targeting unpatched versions of Red Hat Build of Keycloak, SSO 7.0, or JBoss EAP 8.0.0.
  2. Craft malicious sector_identifier_uri: Prepare a client registration or configuration request containing a sector_identifier_uri parameter that points to an attacker-controlled server initially serving a valid JSON response, but configured to issue an HTTP 302 redirect to an internal target (e.g., http://169.254.169.254/latest/meta-data/).
  3. Submit the crafted request: Send the malicious client configuration request to the Keycloak server's client registration or dynamic client configuration endpoint (unauthenticated access may be possible depending on realm configuration).
  4. Trigger SSRF: Keycloak follows the redirect without validating the final destination URL, issuing an HTTP request from its own network context to the internal target.
  5. Infer results: Since this is a blind SSRF, monitor timing differences, error messages, or out-of-band channels (e.g., DNS callbacks, attacker-controlled redirect server logs) to confirm internal service reachability and enumerate internal infrastructure (Red Hat Bugzilla).

Indicators of compromise

  • Network: Outbound HTTP requests from the Keycloak server to internal IP ranges (e.g., 169.254.169.254, RFC 1918 addresses) or unexpected external hosts; unusual DNS lookups originating from the Keycloak host.
  • Logs: Keycloak server logs showing client registration or configuration requests with suspicious sector_identifier_uri values pointing to external or internal redirect chains; HTTP client errors or timeouts related to internal endpoint access attempts.
  • Application: Repeated client registration attempts with varying sector_identifier_uri values from the same source IP, suggesting enumeration activity; unexpected 302 redirect chains logged in Keycloak's HTTP client trace logs.

Mitigation and workarounds

Red Hat has released patches for all affected products: Red Hat Build of Keycloak, Red Hat Single Sign-On 7.0, JBoss Enterprise Application Platform 8.0.0, and JBoss Enterprise Application Platform Expansion Pack. The upstream Keycloak project addressed this in version 26.6.1/26.6.2 (released April 2026) (Keycloak Release). As interim workarounds, administrators should implement network segmentation to prevent the Keycloak server from making outbound requests to internal services and cloud metadata endpoints, disable dynamic client registration if not required, and monitor for suspicious HTTP redirect patterns in client configuration requests (Red Hat CVE, Red Hat Bugzilla).

Community reactions

Coverage of CVE-2026-4366 has been limited to vulnerability tracking platforms and automated security feeds, with no notable researcher commentary or significant social media discussion identified. The Keycloak project acknowledged the fix in its April 2026 release notes (Keycloak Release). The vulnerability was also catalogued by ENISA under EUVD-2026-12762 and tracked by INCIBE-CERT.

Additional resources


SourceThis report was generated using AI

Related JBoss EAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28369CRITICAL9.1
  • Java logoJava
  • pki-core:10.6::resteasy-javadoc
NoYesMar 27, 2026
CVE-2026-28368CRITICAL9.1
  • Java logoJava
  • pki-resteasy-servlet-initializer
NoYesMar 27, 2026
CVE-2026-28367CRITICAL9.1
  • Java logoJava
  • pki-deps:10.6::resteasy
NoYesMar 27, 2026
CVE-2026-3121HIGH7.2
  • Java logoJava
  • cpe:2.3:a:redhat:jboss_enterprise_application_platform
NoYesMar 26, 2026
CVE-2026-4874LOW3.1
  • Java logoJava
  • org.keycloak:keycloak-services
NoYesMar 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management