PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4630 Red Hat CVE debrief

CVE-2026-4630 is an IDOR weakness in Keycloak’s Authorization Services Protection API. An authenticated client that knows or can obtain another Resource Server’s UUID within the same realm may bypass authorization checks and issue unauthorized GET, PUT, and DELETE requests against protected resources. The result can be information disclosure, unauthorized modification, or deletion of data. The vulnerability was published by NVD on 2026-05-19 and is referenced by Red Hat security resources.

Vendor
Red Hat
Product
Red Hat build of Keycloak 26.4
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-06-03
Advisory published
2026-05-19
Advisory updated
2026-06-03

Who should care

Administrators and security teams operating Keycloak deployments that use Authorization Services, especially environments where authenticated clients can interact with the Protection API and Resource Server identifiers may be exposed or guessable.

Technical summary

The issue is described as an IDOR (CWE-639) in the Authorization Services Protection API endpoint. Instead of enforcing object-level authorization for each resource request, the endpoint can be bypassed when an attacker has a valid resource UUID belonging to a different Resource Server in the same realm. The reported impact includes unauthorized read, update, and delete operations.

Defensive priority

High for affected Keycloak Authorization Services deployments; prioritize validation and patching because the flaw can expose or alter protected resources after authentication.

Recommended defensive actions

  • Review Red Hat and NVD advisories for affected Keycloak releases and apply the vendor fix when available.
  • Restrict access to Authorization Services Protection API endpoints to only the clients that truly require it.
  • Audit object-level authorization logic to ensure resource UUIDs cannot be used to bypass ownership or server-bound checks.
  • Review logs for unexpected GET, PUT, or DELETE activity against protected resources, especially from authenticated clients.
  • Inventory realms and resource servers that share Authorization Services so you can identify where UUID exposure could matter.

Evidence notes

All facts in this debrief are drawn from the supplied NVD record and its listed references. The NVD entry classifies the issue as vulnerable status 'Received,' cites Red Hat security references, and lists CWE-639. The product is identified in the source description as Keycloak. No version-specific remediation details were present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-4630 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-4630

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-4630 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4630

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.