CVE-2026-4366 is a medium-severity vulnerability in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects during client configuration requests. This flaw allows an unauthenticated attacker to trick the Keycloak server into making unintended requests to internal or restricted resources. The potential impact includes information disclosure and the ability to map internal network infrastructure, such as accessing sensitive cloud metadata endpoints. Rated with a CVSS score of 5.8, there is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.