Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16071— Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1AI

T1087.004 · Cloud Account

Affected Version Matrix 14

VendorProductVersion RangeStatus
Red HatRed Hat build of Keycloak 26.426.4.14-1< *unaffected
26.4-22< *unaffected
26.4-22< *unaffected
Red HatRed Hat build of Keycloak 26.4.14anyunaffected
anyunaffected
Red HatRed Hat build of Keycloak 26.626.6.5-1< *unaffected
26.6-11< *unaffected
26.6-11< *unaffected
Red HatRed Hat build of Keycloak 26.6.5anyunaffected
anyunaffected
anyunaffected
Red HatRed Hat Data Grid 8anyunaffected
Red HatRed Hat JBoss Enterprise Application Platform Expansion Packanyunaffected
Red HatRed Hat Single Sign-On 7anyunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-16071

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat build of Keycloak 26.4 26.4.14-1 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4.14-cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4.14-cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.6 26.6.5-1 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.5-cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.5-cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.5-cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat Data Grid 8-cpe:/a:redhat:jboss_data_grid:8
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack-cpe:/a:redhat:jbosseapxp
Red HatRed Hat Single Sign-On 7-cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-16071

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16071

登录查看更多情报信息。

Vendor Advisories for CVE-2026-16071 (3)

Other References for CVE-2026-16071 (3)

Same Patch Batch · Red Hat · 2026-08-05 · 14 CVEs total

CVE-2026-100909.9 CRITICALMulticluster-operators-subscription: multicluster-operators-subscription: namespace edit u
CVE-2026-100599.1 CRITICALCluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cl
CVE-2026-155728.8 HIGHKeycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows p
CVE-2026-161028.1 HIGHKeycloak-services: keycloak-services: default dcr policy allows role forgery via user prop
CVE-2026-155738.1 HIGHKeycloak-services: keycloak-services: authorization bypass via unnormalized uri matching i
CVE-2026-164427.4 HIGHKeycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only r
CVE-2026-164437.4 HIGHKeycloak-services: keycloak-services: saml broker metadata import disables response signat
CVE-2026-712267.3 HIGHLibkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot ai
CVE-2026-493316.5 MEDIUMOpenshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on
CVE-2026-161006.5 MEDIUMKeycloak-services: keycloak-services: unbounded metric cardinality in user event metrics v
CVE-2026-712256.5 MEDIUMLibkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state rese
CVE-2026-446055.5 MEDIUMRpm: heap buffer overflow in ndb slot table parsing
CVE-2026-712275.1 MEDIUMLibkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandl

IV. Related Vulnerabilities

V. Comments for CVE-2026-16071

No comments yet


Leave a comment