Tag
Keycloak Stateless Mode Replay Vulnerability (CVE-2026-90997)
1 TTP 1 CVEA row-count mismatch in Keycloak when using MySQL or MariaDB in stateless mode allows attackers to bypass replay protection for single-use security artifacts like JWT client assertions, DPoP proofs, or TOTP codes.
Critical Vulnerabilities in Cisco Identity Services Engine and ISE-PIC
3 TTPs 2 CVEsMultiple vulnerabilities, including one actively exploited in the wild (CVE-2026-76460), allow unauthenticated attackers to bypass authentication and gain administrative control over Cisco ISE and ISE-PIC deployments.
Denial of Service Vulnerability in Keycloak Theme Localization
1 rule 1 TTP 1 CVEAn unauthenticated denial-of-service vulnerability in Keycloak (CVE-2026-79651) allows attackers to exhaust server memory by injecting arbitrary locale tags into an unbounded cache.
Arbitrary Command Execution in Snipe-IT Backup Restoration
1 rule 14 TTPs 1 CVESnipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.
Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw
3 TTPs 3 CVEsAn unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.
Privilege Escalation in FreeIPA via Kerberos Principal Name Collision
1 TTP 1 CVECVE-2026-13097 is a privilege escalation vulnerability in FreeIPA where the 389-ds directory server fails to enforce uniqueness constraints on Kerberos principal names, allowing attackers with LDAP write access to impersonate privileged service principals.
Critical Authentication Bypass in Red Hat Build of Keycloak
1 TTP 1 CVEA critical vulnerability (CVE-2026-18963) in the keycloak-services component allows unauthenticated attackers to hijack user accounts by bypassing password reset verification requirements.
Authenticated Identity Spoofing Vulnerability in Velociraptor
1 CVERapid7 Velociraptor versions prior to 0.77.2 are affected by an authenticated identity-spoofing vulnerability, CVE-2026-18972, that may allow unauthorized access or impersonation within the platform.
Privilege Escalation in Keycloak Dynamic Client Registration
1 TTP 1 CVEA vulnerability in Keycloak's Dynamic Client Registration component allows authenticated users with an Initial Access Token to forge administrative roles via improper claim validation.
CVE-2026-16443: Signature Validation Bypass in Keycloak SAML Metadata Import
2 TTPs 1 CVEAn authentication bypass vulnerability in Red Hat Build of Keycloak allows unauthenticated attackers to forge SAML assertions by manipulating metadata import settings to disable signature validation.
Insufficient Redirect URI Validation in MaxKey
2 TTPs 1 CVEMaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.
Zitadel User API Verification Code Disclosure Vulnerability
1 TTP 1 CVEAn improper permission check in Zitadel's user API allows authenticated users to retrieve verification codes for arbitrary contact information, facilitating unauthorized verification of email addresses and phone numbers.
Keycloak JWT Authorization Bypass via Disabled User Accounts (CVE-2026-1609)
1 TTP 1 CVEA vulnerability exists in Keycloak when its JSON Web Token (JWT) authorization grant preview feature is enabled, allowing a remote attacker with low privileges to exploit CVE-2026-1609 by presenting a valid assertion token from an external identity provider to obtain a JWT for a user account that has been disabled, thereby bypassing access controls and gaining unauthorized access to sensitive resources.
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints (CVE-2026-45052)
2 TTPsAn improper authorization vulnerability (CVE-2026-45052) in OpenAM Community Edition through version 16.0.6 allows an unauthenticated attacker to write persistent entries into the Liberty Discovery store on any user's LDAP entry and a shared root-realm Discovery branch, due to a flaw in the Liberty Web Services SOAP receiver that permits anonymous writes with elevated internal privileges, potentially influencing service routing or security mechanisms if Liberty discovery data is consumed.
Okta Application Modified or Deleted
2 rules 1 TTPDetects when an Okta application is modified or deleted, potentially indicating unauthorized changes or removal of critical applications.