Description
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
Published: 2026-08-05
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Keycloak’s LDAP storage provider allows a delegated administrator to perform a search using a specific LDAP entry Distinguished Name (DN) that bypasses the configured user DN boundary. Because the provider does not validate the search boundary, the lookup can return entries located outside the intended subtree, revealing account information that the administrator is not authorized to see and potentially importing those accounts into the local Keycloak storage. The primary consequence is loss of confidentiality and accidental expansion of the local user base.

Affected Systems

The vulnerability affects Red Hat’s build of Keycloak 26.4, 26.4.14, 26.6, and 26.6.5, as well as Red Hat Data Grid 8, the JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. Any installation that uses the LDAP storage provider and assigns delegated administrator permissions is vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score is below 1%, suggesting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack, as described, requires an authenticated delegated administrator who can craft a search with a specific entry DN. The observed risk is limited to environments where many users have delegated administrator roles; the potential for data disclosure exists, but the probability remains low.

Generated by OpenCVE AI on August 6, 2026 at 18:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Red Hat errata update RHSA‑2026:50846, RHSA‑2026:50847, RHSA‑2026:50848, or RHSA‑2026:50849 that addresses the LDAP DN validation flaw.
  • If a patch is not yet available, revoke or limit delegated administrator permissions and enforce a strict DN boundary in the LDAP search configuration.
  • Monitor LDAP query logs for unexpected search patterns and audit local user imports for accounts originating outside the intended directory scope.

Generated by OpenCVE AI on August 6, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Thu, 06 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-200

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
References

Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-200

Wed, 05 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
Title Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid 8 Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-06T14:18:08.739Z

Reserved: 2026-07-17T13:18:14.328Z

Link: CVE-2026-16071

cve-icon Vulnrichment

Updated: 2026-08-06T14:17:56.007Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T15:16:37.440

Modified: 2026-08-10T18:37:16.177

Link: CVE-2026-16071

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-05T02:02:00Z

Links: CVE-2026-16071 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:06:24Z

Weaknesses
  • CWE-269

    Improper Privilege Management