Changeflow GovPing Data Privacy & Cybersecurity Keycloak Vulnerability Allows Information Discl...
Priority review Notice Added Final

Keycloak Vulnerability Allows Information Disclosure

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 17th, 2026
Detected March 18th, 2026
Email

Summary

CERT-Bund has issued a security advisory regarding a vulnerability in Keycloak that allows for information disclosure. The vulnerability affects Keycloak versions running on Linux and UNIX operating systems. Users are advised to consult the advisory for mitigation details.

What changed

CERT-Bund has released a security advisory (WID-SEC-2026-0768) detailing a vulnerability in Keycloak, a popular open-source identity and access management solution. The vulnerability, with a CVSS Base Score of 5.8, allows remote, anonymous attackers to disclose information. This advisory applies to Keycloak versions running on Linux and UNIX operating systems.

Organizations utilizing Keycloak should review the advisory to understand the potential impact and implement necessary mitigation strategies. While the advisory does not specify a compliance deadline, prompt action is recommended to address the information disclosure risk. Further details and specific mitigation steps can be found via the provided CVE and information links.

What to do next

  1. Review CERT-Bund security advisory WID-SEC-2026-0768 for Keycloak vulnerability.
  2. Assess the impact of the information disclosure vulnerability on your Keycloak instances.
  3. Implement recommended mitigation strategies provided by CERT-Bund or Keycloak.

Source document (simplified)

[WID-SEC-2026-0768] Keycloak: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 5.8 (mittel) CVSS Temporal Score 5.3 (mittel) Remoteangriff ja Datum 17.03.2026 Stand 18.03.2026 Mitigation nein

Betroffene Systeme

Betriebssystem

  • Linux
  • UNIX

Produktbeschreibung

Keycloak ermöglicht Single Sign-On mit Identity and Access Management für moderne Anwendungen und Dienste.

Produkte

17.03.2026
- Open Source Keycloak

Angriff

Angriff

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 17th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Technology companies
Geographic scope
de

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Information Security Software Vulnerabilities

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.