PatchSiren cyber security CVE debrief
CVE-2026-4630 Red Hat CVE debrief
CVE-2026-4630 is an IDOR weakness in Keycloak’s Authorization Services Protection API. An authenticated client that knows or can obtain another Resource Server’s UUID within the same realm may bypass authorization checks and issue unauthorized GET, PUT, and DELETE requests against protected resources. The result can be information disclosure, unauthorized modification, or deletion of data. The vulnerability was published by NVD on 2026-05-19 and is referenced by Red Hat security resources.
- Vendor
- Red Hat
- Product
- Red Hat build of Keycloak 26.4
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-06-03
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-06-03
Who should care
Administrators and security teams operating Keycloak deployments that use Authorization Services, especially environments where authenticated clients can interact with the Protection API and Resource Server identifiers may be exposed or guessable.
Technical summary
The issue is described as an IDOR (CWE-639) in the Authorization Services Protection API endpoint. Instead of enforcing object-level authorization for each resource request, the endpoint can be bypassed when an attacker has a valid resource UUID belonging to a different Resource Server in the same realm. The reported impact includes unauthorized read, update, and delete operations.
Defensive priority
High for affected Keycloak Authorization Services deployments; prioritize validation and patching because the flaw can expose or alter protected resources after authentication.
Recommended defensive actions
- Review Red Hat and NVD advisories for affected Keycloak releases and apply the vendor fix when available.
- Restrict access to Authorization Services Protection API endpoints to only the clients that truly require it.
- Audit object-level authorization logic to ensure resource UUIDs cannot be used to bypass ownership or server-bound checks.
- Review logs for unexpected GET, PUT, or DELETE activity against protected resources, especially from authenticated clients.
- Inventory realms and resource servers that share Authorization Services so you can identify where UUID exposure could matter.
Evidence notes
All facts in this debrief are drawn from the supplied NVD record and its listed references. The NVD entry classifies the issue as vulnerable status 'Received,' cites Red Hat security references, and lists CWE-639. The product is identified in the source description as Keycloak. No version-specific remediation details were present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4630 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4630
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4630 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4630
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:19596
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:19597
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-4630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.