
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4874 is a Server-Side Request Forgery (SSRF) vulnerability in Keycloak, specifically within the OIDC token endpoint (org.keycloak.protocol.oidc.grants and org.keycloak.services.managers). An authenticated attacker can manipulate the client_session_host parameter during refresh token requests to cause the Keycloak server to issue arbitrary HTTP requests from its own network context. The vulnerability was disclosed on March 26, 2026, and affects Red Hat Single Sign-On 7.0, Red Hat build of Keycloak, JBoss Enterprise Application Platform 8.0.0, and the JBoss EAP Expansion Pack. It carries a CVSS v3.1 base score of 3.1 (Low) (Red Hat CVE, Red Hat Bugzilla).
The root cause is improper neutralization of user-supplied input in the SSRF category (CWE-918). When a Keycloak client is configured with backchannel.logout.url using the application.session.host placeholder, Keycloak substitutes the attacker-controlled client_session_host value from the refresh token request into this URL and issues a server-side HTTP POST to the resulting address upon logout (triggered by admin action, user logout, or session timeout). Exploitation requires three preconditions: valid credentials to obtain a refresh token, a client configured with backchannel.logout.url using the application.session.host placeholder, and a logout event. The attack is classified as a "blind SSRF" because the attacker does not directly receive the HTTP response but can probe internal endpoints including cloud metadata services and internal APIs (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation allows an authenticated attacker to make HTTP requests originating from the Keycloak server's network context, enabling reconnaissance of internal networks, cloud metadata services (e.g., AWS IMDSv1), and internal APIs that are not externally reachable. The primary impact is information disclosure (confidentiality: Low), with no direct integrity or availability impact. While the CVSS score is low, the ability to probe internal infrastructure from a trusted server could facilitate further lateral movement or privilege escalation in environments with inadequate network segmentation (Red Hat CVE, Red Hat Bugzilla).
backchannel.logout.url using the application.session.host placeholder — this configuration is required for exploitation.169.254.169.254) into the client_session_host parameter.client_session_host value into the backchannel.logout.url and issues an HTTP POST to the resulting URL from the server's network context.10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or cloud metadata endpoints (e.g., 169.254.169.254) during backchannel logout processing.client_session_host parameter values in the OIDC token endpoint access logs.client_session_host value does not match expected client IP ranges.Patches are available via Red Hat advisories RHSA-2026:25097 and RHSA-2026:25098, and the upstream Keycloak 26.6.3 release addresses this vulnerability (Red Hat RHSA-25098, Red Hat RHSA-25097, Keycloak 26.6.3). As an immediate workaround, administrators should audit and remove the application.session.host placeholder from any backchannel.logout.url client configurations where it is not strictly required. Additionally, implementing network segmentation to restrict the Keycloak server's outbound HTTP access to only necessary endpoints will limit the blast radius of exploitation. Monitoring refresh token requests for anomalous client_session_host values is also recommended.
The vulnerability was noted in the CTI Pilot weekly brief for 2026-W23, which highlighted it as part of a broader Keycloak 26.6.3 release addressing 16 CVEs relevant to the EU public sector's reference IAM platform (CTI Pilot W23). Community tracking was observed across multiple vulnerability aggregators and a Bluesky post from the CVE Skyfleet account. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."