CVE Record
[ MEDIUM ]CVE-2026-94215
Keycloak Admin REST API client cache flaw
A per-request in-memory cache in the Keycloak Admin REST API resolves clients by client_id incorrectly, potentially allowing unintended client resolution. Red Hat rates this CVSS 5.5 medium.
- Vendor
- Red Hat
- Product
- Keycloak
- CVSS
- 5.5
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
The Admin REST API in Keycloak uses a per-request in-memory cache to resolve clients by client_id. A flaw in that resolution logic can lead to unintended client resolution. Red Hat did not fully disclose the scope or exploitation conditions in the published advisory.
Red Hat rates this CVSS 5.5 (medium). No active exploitation reported. Patched versions are listed in the Red Hat advisory.
