A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
rhbk/keycloak Red Hat / RHEL
Fixed in: rhel9@sha256:a4cb583985eb220ad05b1983a98a5a50e2b76c15e6f56152045591e3994f37d1_ppc64le RHSA-2026:6478 Fixed in: rhel9-operator@sha256:715a5c6cc9061fc0305370a33f5b69a96ba7bfdb23b706a567b489fc05b05e06_ppc64le RHSA-2026:6478 Fixed in: rhel9@sha256:dc54248ad9357fbd737e6983e6d8d0c7e845e39ed6558bd7c39f7a7573459489_amd64 RHSA-2026:6478 Fixed in: operator-bundle@sha256:7fb041b0e2b43954c3a83b58fd885b1cdc5bb32275e06c4c72955da5b78255c3_amd64 RHSA-2026:6478 Fixed in: rhel9-operator@sha256:1a7ac3c798d83cc37dd750ed44223630f4ebff937534a59a9e9ad029dbf31a0f_amd64 RHSA-2026:6478 Fixed in: rhel9@sha256:c1c1cb36f70ca142a789b359f9a120d321f58adc44e2c97a49c2d6f270d15bd9_arm64 RHSA-2026:6478 Fixed in: rhel9-operator@sha256:c68d195c2d19568d9789648ef347a3388da453c83120d696453333c34a564347_arm64 RHSA-2026:6478 Fixed in: rhel9@sha256:33fc8c6edb3c5c2df302ea53a89454320e08ff4660ba84d0a78f6c67178dfb16_s390x RHSA-2026:6478 Fixed in: rhel9-operator@sha256:0d90a1c28652b5f73ea90f78968548178cf710121fcb13774a467aeb9c30ab09_s390x RHSA-2026:6478 Fixed in: rhel9@sha256:b3fe3f4c74e96a2daf735fe5e8df98b2fa6f023cfda0c7cd4915a83556e14efb_amd64 RHSA-2026:6476 Fixed in: operator-bundle@sha256:d80f27078e17321d4b194820a9c325c47b8cc3e431ac37c84a6c5b2b52b009e6_amd64 RHSA-2026:6476 Fixed in: rhel9-operator@sha256:31378e237970d0c5c483ec2dd3de6a39adfb7cdfe13c5d106be39088859271e6_amd64 RHSA-2026:6476 Fixed in: rhel9@sha256:4065d584a57daa2aa2259afa19844f6308e2f6a252b08738c809002cc84aa606_s390x RHSA-2026:6476 Fixed in: rhel9-operator@sha256:6c0c1d05bb893e1d598ffc5e953f1287d36e78f6b1938c430e0bc19e22343ae4_s390x RHSA-2026:6476 Fixed in: rhel9@sha256:4c4f3e098f715efc174a4a01803b7133ca7c2b744ea4b8151c7edcae608d9531_ppc64le RHSA-2026:6476 Fixed in: rhel9-operator@sha256:47fa46896eda2f3c51657f6bc9a024d63f3d306f4726ead3fa46ef5796696e07_ppc64le RHSA-2026:6476 Fixed in: rhel9@sha256:10b97dd8e38ce50457a121e53d53472877cc3aa185e7c4b23da191c00e914af2_arm64 RHSA-2026:6476 Fixed in: rhel9-operator@sha256:1880e406eab1303dd1faa08694ff2cb33901e1e69272a2f9cdf5f5af6941bd84_arm64 RHSA-2026:6476 rhbk/keycloak Rocky
Fixed in: rhel9@sha256:a4cb583985eb220ad05b1983a98a5a50e2b76c15e6f56152045591e3994f37d1_ppc64le RHSA-2026:6478 Fixed in: rhel9-operator@sha256:715a5c6cc9061fc0305370a33f5b69a96ba7bfdb23b706a567b489fc05b05e06_ppc64le RHSA-2026:6478 Fixed in: rhel9@sha256:dc54248ad9357fbd737e6983e6d8d0c7e845e39ed6558bd7c39f7a7573459489_amd64 RHSA-2026:6478 Fixed in: operator-bundle@sha256:7fb041b0e2b43954c3a83b58fd885b1cdc5bb32275e06c4c72955da5b78255c3_amd64 RHSA-2026:6478 Fixed in: rhel9-operator@sha256:1a7ac3c798d83cc37dd750ed44223630f4ebff937534a59a9e9ad029dbf31a0f_amd64 RHSA-2026:6478 Fixed in: rhel9@sha256:c1c1cb36f70ca142a789b359f9a120d321f58adc44e2c97a49c2d6f270d15bd9_arm64 RHSA-2026:6478 Fixed in: rhel9-operator@sha256:c68d195c2d19568d9789648ef347a3388da453c83120d696453333c34a564347_arm64 RHSA-2026:6478 Fixed in: rhel9@sha256:33fc8c6edb3c5c2df302ea53a89454320e08ff4660ba84d0a78f6c67178dfb16_s390x RHSA-2026:6478 Fixed in: rhel9-operator@sha256:0d90a1c28652b5f73ea90f78968548178cf710121fcb13774a467aeb9c30ab09_s390x RHSA-2026:6478 Fixed in: rhel9@sha256:b3fe3f4c74e96a2daf735fe5e8df98b2fa6f023cfda0c7cd4915a83556e14efb_amd64 RHSA-2026:6476 Fixed in: operator-bundle@sha256:d80f27078e17321d4b194820a9c325c47b8cc3e431ac37c84a6c5b2b52b009e6_amd64 RHSA-2026:6476 Fixed in: rhel9-operator@sha256:31378e237970d0c5c483ec2dd3de6a39adfb7cdfe13c5d106be39088859271e6_amd64 RHSA-2026:6476 Fixed in: rhel9@sha256:4065d584a57daa2aa2259afa19844f6308e2f6a252b08738c809002cc84aa606_s390x RHSA-2026:6476 Fixed in: rhel9-operator@sha256:6c0c1d05bb893e1d598ffc5e953f1287d36e78f6b1938c430e0bc19e22343ae4_s390x RHSA-2026:6476 Fixed in: rhel9@sha256:4c4f3e098f715efc174a4a01803b7133ca7c2b744ea4b8151c7edcae608d9531_ppc64le RHSA-2026:6476 Fixed in: rhel9-operator@sha256:47fa46896eda2f3c51657f6bc9a024d63f3d306f4726ead3fa46ef5796696e07_ppc64le RHSA-2026:6476 Fixed in: rhel9@sha256:10b97dd8e38ce50457a121e53d53472877cc3aa185e7c4b23da191c00e914af2_arm64 RHSA-2026:6476 Fixed in: rhel9-operator@sha256:1880e406eab1303dd1faa08694ff2cb33901e1e69272a2f9cdf5f5af6941bd84_arm64 RHSA-2026:6476 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Impact
Confidentiality High
Integrity High
Availability None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
0.42% probability of exploitation in 30 days
35th percentile
Low risk: more likely to be exploited than 35% of all known CVEs.
Other CWE-653 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2026-4282 Markdown
[](https://tridentstack.com/cve/CVE-2026-4282)HTML
<a href="https://tridentstack.com/cve/CVE-2026-4282"><img src="https://tridentstack.com/cve/badge/CVE-2026-4282.svg" alt="CVE-2026-4282"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-07-15.