CVE-2026-3872
Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.15, Red Hat build of Keycloak 26.4 취약점
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.
- 대응 우선순위
- 점검
- CVSS
- 7.3
- EPSS
- 0.44% 백분위 36.2% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.02