Keycloak 26.6.x < 26.6.6 Multiple Vulnerabilities

high Nessus Plugin ID 338316

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Keycloak installed on the remote host is 26.6.x prior to 26.6.6. It is, therefore, affected by multiple vulnerabilities:

- A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim. (CVE-2026-15571)

- A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they should not have access to. When Fine-Grained Admin Permissions (FGAP v2) are enabled, an administrator who is allowed to see a specific role can also see a list of all groups assigned to that role, because the system fails to check whether the administrator has permission to view those specific groups. (CVE-2026-14613)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade Keycloak to version 26.6.6 or later.

See Also

https://access.redhat.com/errata/RHSA-2026:56523

https://access.redhat.com/errata/RHSA-2026:56524

https://access.redhat.com/security/cve/CVE-2026-14613

https://access.redhat.com/security/cve/CVE-2026-15571

Plugin Details

Severity: High

ID: 338316

File Name: keycloak_26_6_6.nasl

Version: 1.1

Type: Local

Agent: unix

Family: Misc.

Published: 8/20/2026

Updated: 8/20/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.52

CVSS v2

Risk Factor: High

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-15571

CVSS v3

Risk Factor: High

Base Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/a:keycloak:keycloak

Required KB Items: Host/local_checks_enabled, Host/uname, installed_sw/Keycloak

Patch Publication Date: 8/18/2026

Vulnerability Publication Date: 7/3/2026

Reference Information

CVE: CVE-2026-14613, CVE-2026-15571