Feed/CVE-2026-4630
CVE-2026-4630MEDIUMCVSS 6.8

Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers

Published May 19, 2026·Updated Jun 30, 2026

NVD Description

Keycloak's Authorization Services feature exposes a User-Managed Access Protection API that include an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, an authenticated client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.

Affected Packages (1)

org.keycloak:keycloak-servicesMAVEN
Fixed in 26.6.2

Public Exploits & PoCs9 found

[POC] CVE-2026-46300 — CVE-2026-46300

CVE-2026-43284 - CVE-2026-43500 - CVE-2026-46300 Variant of dirtyfrag exploit

1

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-46300

Technical analysis of CVE-2026-46300 (Fragnesia), a Linux kernel page-cache write vulnerability that enables local privilege escalation through SKBFL_SHARED_FRAG invariant violations in the networking stack.

[POC] CVE-2026-46300 — CVE-2026-46300-Fragnesia---TryHackMe-Lab-Project

The project documents the completion and analysis of the Fragnesia (CVE-2026-46300) TryHackME lab, which demonstrates a Linux kernel page -cache corruption vulnerability capable of achieving local privilege escalation through modification of cached file pages without altering files on disk.

[POC] CVE-2026-46300 — CVE-2026-46300-Fragnesia---TryHackMe-Lab-Walkthrough

This project documents the completion and analysis of the Fragnesia (CVE-2026-46300) TryHackMe lab, which demonstrates a Linux kernel page-cache corruption vulnerability capable of achieving local priviledge escalation through modification of cached file pages without altering files on disk.

[POC] CVE-2026-46300 — Fragnesia

Add go CVE-2026-46300 (Fragnesia) local privilege escalation exploit

[POC] CVE-2026-46300 — Fragnesia-go

A Go implementation of fragnesia (CVE-2026-46300)

[POC] CVE-2026-46300 — CVE-2026-46300

Linux kernel root exploit

[POC] CVE-2026-46300 — CVE-2026-46300

CVE-2026-46300

[POC] CVE-2026-46300 — CVE-2026-46300

CVE-2026-46300

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free