Red Hat build of Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*
- >= 26.2.0, < 26.2.11
- >= 26.4.0, < 26.4.6
A deserialization vulnerability has been identified in the Red Hat build of Keycloak LDAP User Federation provider, specifically in versions 26.2.11 and 26.4.6. This flaw allows an authenticated realm administrator to exploit a malicious LDAP server configuration, leading to the deserialization of untrusted Java objects.
Exploitation of this vulnerability could allow an attacker to manipulate deserialized objects or data, potentially modifying application data or causing an unexpected state. In some cases, such deserialization vulnerabilities can be leveraged to execute arbitrary code.
Users can upgrade to the Red Hat build of Keycloak 26.4.6, which is available through the Red Hat Customer Portal. For those using Keycloak 26.2.11, new images are also available on the Customer Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.