Category

security

Articles about security from the Skycloak team.

security

Device Code Phishing and Passkey Lures: Harden Keycloak Against AiTM

Microsoft's September 2026 report shows passkey-themed lures driving AiTM and device-code attacks. Here is the Keycloak realm hardening that answers…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-17048: Keycloak’s Admin REST API Can Hand Back a Vault-Resolved Client Secret

CVE-2026-17048 lets a view-only Keycloak admin read the plaintext of a vault-backed rotated client secret. CVSS 5.5, fixed in 26.7.2…

Guilliano Molaire Guilliano Molaire 9 min read
security

CVE-2026-82968: Hardening Keycloak First-Broker Login While the Fix Is Pending

CVE-2026-82968 lets an attacker on the same social provider intercept Keycloak account linking. CVSS 6.4, no patched release yet. What…

Guilliano Molaire Guilliano Molaire 8 min read
security

CVE-2026-18963: The Keycloak Password Reset Takeover, and Which Versions Fix It

CVE-2026-18963 lets an unauthenticated attacker take over any Keycloak account through the reset-credentials flow. CVSS 9.1. Three release lines carry…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-88770: Keycloak’s Device Flow Can Still Issue Tokens for a Locked Account

CVE-2026-88770 lets Keycloak's device authorization grant redeem tokens for an account brute-force protection already locked. CVSS 6.5, no patch yet.

Guilliano Molaire Guilliano Molaire 8 min read
security

Keycloak 26.7.3 Security Fixes: A Self-Hosted Patch Checklist

Keycloak 26.7.3 fixes twenty CVEs across FGAP v2, OIDC and token exchange. What to re-test after you upgrade, and which…

Guilliano Molaire Guilliano Molaire 9 min read
security

Keycloak LDAP Certificate Validation: What CVE-2026-35563 Actually Affects

CVE-2026-35563 is scoped to a Keycloak test dependency, not LDAP user federation. Here is what really governs LDAP certificate validation…

Guilliano Molaire Guilliano Molaire 7 min read
security

CVE-2026-16072 and CVE-2026-18201: Two Keycloak Organization Permission Gaps

Two moderate Keycloak CVEs let admins act outside their permissions on organizations. What they allow, who is affected, and what…

Guilliano Molaire Guilliano Molaire 7 min read
best-practices

SPIFFE/SPIRE Workload Identity: What a Compromised Node Actually Breaks

Unit 42 showed a root-compromised Kubernetes node can spoof SPIFFE/SPIRE workload identities via cgroup tricks. Here is what actually breaks,…

Guilliano Molaire Guilliano Molaire 11 min read
Snowy checkpoint with a mint-green guard booth, barrier gate, and filing cabinets outside; a person in a warm coat stands in the window.
Keycloak

Loi 25 et PIPEDA : ce que la conformité exige de votre système d’identité

Ce que la Loi 25 et la LPRPDE exigent de votre gestion des identités, où vos données doivent résider, et…

Guilliano Molaire Guilliano Molaire 9 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman