
Critical Vulnerabilities Discovered in Keycloak Allowing Security Bypass
Keycloakvulnerabilitiessecurity_bypassCERT-FRPoCunauthorized_accesscybersecurity
Multiple vulnerabilities were discovered in Keycloak on 25 August 2026, as reported by the CERT-FR in advisory CERTFR-2026-AVI-1078. These flaws allow attackers to bypass security policies and exploit an unspecified security issue as described by the vendor. The CERT-FR confirmed the existence of a public proof-of-concept (PoC) for at least one of the vulnerabilities. No specific CVE IDs, affected versions, or additional technical details were provided in the notice. The impacts include potential unauthorized access or security control circumvention within Keycloak deployments.