Skip to content

CVE-2026-4282 Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw #47719

@stianst

Description

@stianst

Keycloak's SingleUseObjectProvider is a global flat key-value store used by multiple features without type or namespace isolation. This allows an unauthenticated attacker to forge authorization codes and mint admin-capable access tokens.

Metadata

Metadata

Assignees

Type

No fields configured for cve.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions