Skip to content
Threat Feed

Tag

Identity-Management

15 briefs RSS
high advisory

Keycloak Stateless Mode Replay Vulnerability (CVE-2026-90997)

A row-count mismatch in Keycloak when using MySQL or MariaDB in stateless mode allows attackers to bypass replay protection for single-use security artifacts like JWT client assertions, DPoP proofs, or TOTP codes.

Keycloak identity-management authentication-bypass vulnerability
1t 1c
critical threat

Critical Vulnerabilities in Cisco Identity Services Engine and ISE-PIC

Multiple vulnerabilities, including one actively exploited in the wild (CVE-2026-76460), allow unauthenticated attackers to bypass authentication and gain administrative control over Cisco ISE and ISE-PIC deployments.

exploited Identity Services Engine +1 vulnerability cisco identity-management authentication-bypass
3t 2c
low advisory

Denial of Service Vulnerability in Keycloak Theme Localization

An unauthenticated denial-of-service vulnerability in Keycloak (CVE-2026-79651) allows attackers to exhaust server memory by injecting arbitrary locale tags into an unbounded cache.

Keycloak denial-of-service vulnerability identity-management
1r 1t 1c
high advisory

Arbitrary Command Execution in Snipe-IT Backup Restoration

Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.

Snipe-IT +1 remote-code-execution cve vulnerability web-vulnerability css-injection account-takeover cve-2026-86751 ssrf +8
1r 14t 1c updated
critical advisory

Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw

An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.

FreeIPA +2 identity-management authentication-bypass privilege-escalation ldap vulnerability cve linux
3t 3c updated
high advisory

Privilege Escalation in FreeIPA via Kerberos Principal Name Collision

CVE-2026-13097 is a privilege escalation vulnerability in FreeIPA where the 389-ds directory server fails to enforce uniqueness constraints on Kerberos principal names, allowing attackers with LDAP write access to impersonate privileged service principals.

FreeIPA privilege-escalation identity-management kerberos
1t 1c
critical advisory

Critical Authentication Bypass in Red Hat Build of Keycloak

A critical vulnerability (CVE-2026-18963) in the keycloak-services component allows unauthenticated attackers to hijack user accounts by bypassing password reset verification requirements.

PoC Red Hat Build of Keycloak +1 authentication-bypass identity-management cve-2026-18963
1t 1c updated
high advisory

Authenticated Identity Spoofing Vulnerability in Velociraptor

Rapid7 Velociraptor versions prior to 0.77.2 are affected by an authenticated identity-spoofing vulnerability, CVE-2026-18972, that may allow unauthorized access or impersonation within the platform.

Velociraptor vulnerability identity-management
1c
high advisory

Privilege Escalation in Keycloak Dynamic Client Registration

A vulnerability in Keycloak's Dynamic Client Registration component allows authenticated users with an Initial Access Token to forge administrative roles via improper claim validation.

Keycloak privilege-escalation identity-management
1t 1c
high advisory

CVE-2026-16443: Signature Validation Bypass in Keycloak SAML Metadata Import

An authentication bypass vulnerability in Red Hat Build of Keycloak allows unauthenticated attackers to forge SAML assertions by manipulating metadata import settings to disable signature validation.

Red Hat Build of Keycloak authentication-bypass saml identity-management
2t 1c
medium advisory

Insufficient Redirect URI Validation in MaxKey

MaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.

MaxKey oauth identity-management cve-2026-67345
2t 1c
low advisory

Zitadel User API Verification Code Disclosure Vulnerability

An improper permission check in Zitadel's user API allows authenticated users to retrieve verification codes for arbitrary contact information, facilitating unauthorized verification of email addresses and phone numbers.

Zitadel 4.x +2 identity-management auth-bypass api-security
1t 1c
high advisory

Keycloak JWT Authorization Bypass via Disabled User Accounts (CVE-2026-1609)

A vulnerability exists in Keycloak when its JSON Web Token (JWT) authorization grant preview feature is enabled, allowing a remote attacker with low privileges to exploit CVE-2026-1609 by presenting a valid assertion token from an external identity provider to obtain a JWT for a user account that has been disabled, thereby bypassing access controls and gaining unauthorized access to sensitive resources.

Keycloak identity-management authorization-bypass jwt access-control
1t 1c
critical advisory

OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints (CVE-2026-45052)

An improper authorization vulnerability (CVE-2026-45052) in OpenAM Community Edition through version 16.0.6 allows an unauthenticated attacker to write persistent entries into the Liberty Discovery store on any user's LDAP entry and a shared root-realm Discovery branch, due to a flaw in the Liberty Web Services SOAP receiver that permits anonymous writes with elevated internal privileges, potentially influencing service routing or security mechanisms if Liberty discovery data is consumed.

OpenAM Community Edition +1 vulnerability identity-management web-application openam
2t
medium advisory

Okta Application Modified or Deleted

Detects when an Okta application is modified or deleted, potentially indicating unauthorized changes or removal of critical applications.

Okta application-security identity-management
2r 1t