Red Hat disclosed CVE-2026-4636, a high-severity flaw in Keycloak that lets an authenticated user with the uma_protection role bypass User-Managed Access (UMA) policy validation. By submitting policy creation requests that reference resource identifiers owned by other users while the URL path points to an attacker-controlled resource, an attacker can obtain a Requesting Party Token (RPT) for victim-owned resources. The issue can expose sensitive information and permit unauthorized actions against protected resources; Red Hat linked the vulnerability to advisories RHSA-2026:6477 and RHSA-2026:6478.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-07, Red Hat received and recorded CVE-2026-4740 affecting Open Cluster Management, describing improper Kubernetes client certificate renewal validation that could enable cross-cluster privilege escalation.
Later on 2026-04-02, Red Hat modified the CVE-2026-4636 entry to add references to advisories RHSA-2026:6477 and RHSA-2026:6478.
Red Hat recorded CVE-2026-4636 on 2026-04-02 for a Keycloak flaw that lets an authenticated user with the uma_protection role bypass UMA policy validation and gain unauthorized access to victim-owned resources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.