Category

security

Articles about security from the Skycloak team.

security

Shadow AI Agents: Okta’s Endpoint Scan vs Keycloak Inventory

Okta widened shadow AI agent discovery at Oktane 2026. Keycloak has no endpoint scanner, but it owns the chokepoint where…

Guilliano Molaire Guilliano Molaire 9 min read
security

MFA Fatigue and Keycloak: The Real Risk Is Enrollment Abuse

Keycloak 26.x ships no push authenticator, so MFA fatigue lands differently here. The exposure that matters is authenticator enrollment, and…

Guilliano Molaire Guilliano Molaire 8 min read
security

CVE-2026-17526: Keycloak Impersonation Escalates to Realm Admin

CVE-2026-17526 let a Keycloak impersonation-role holder take over a realm admin. Fixed in 26.7.4 on 16 September 2026, and on…

Guilliano Molaire Guilliano Molaire 8 min read
security

CVE-2026-59822: LiteLLM’s MCP Auth Bypass, and the Second Bug in the Same Fix

CVE-2026-59822 let any fabricated Bearer token open a LiteLLM MCP session. The two separate bugs one pull request closed, and…

Guilliano Molaire Guilliano Molaire 11 min read
security

CVE-2026-93999: Keycloak Refresh Restores a Disabled Audience

Keycloak checks an audience client is enabled during token exchange, but not when that refresh token is used. What CVE-2026-93999…

Guilliano Molaire Guilliano Molaire 9 min read
security

Device Code Phishing and Passkey Lures: Harden Keycloak Against AiTM

Microsoft's September 2026 report shows passkey-themed lures driving AiTM and device-code attacks. Here is the Keycloak realm hardening that answers…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-17048: Keycloak’s Admin REST API Can Hand Back a Vault-Resolved Client Secret

CVE-2026-17048 lets a view-only Keycloak admin read the plaintext of a vault-backed rotated client secret. CVSS 5.5, fixed in 26.7.2…

Guilliano Molaire Guilliano Molaire 9 min read
security

CVE-2026-88770: Keycloak’s Device Flow Can Still Issue Tokens for a Locked Account

CVE-2026-88770 lets Keycloak's device authorization grant redeem tokens for an account brute-force protection already locked. CVSS 6.5, no patch yet.

Guilliano Molaire Guilliano Molaire 8 min read
security

CVE-2026-18963: The Keycloak Password Reset Takeover, and Which Versions Fix It

CVE-2026-18963 lets an unauthenticated attacker take over any Keycloak account through the reset-credentials flow. CVSS 9.1. Three release lines carry…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-82968: Hardening Keycloak First-Broker Login While the Fix Is Pending

CVE-2026-82968 lets an attacker on the same social provider intercept Keycloak account linking. CVSS 6.4, no patched release yet. What…

Guilliano Molaire Guilliano Molaire 8 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman