CVE-2026-16071 Details
Description
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
A vulnerability exists in the LDAP storage provider of Keycloak, allowing delegated administrators to bypass configured search boundaries when querying user identities via LDAP entry Distinguished Names (DNs). This flaw arises from inadequate validation, enabling access to account information from unauthorized parts of the directory and inadvertently importing those users into local storage. The issue affects Red Hat Build of Keycloak.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:50846 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50847 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50848 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50849 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-16071 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2501720 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-90 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') | [email protected] |
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.14 >= 26.6, < 26.6.5 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 5, 2026 | New CVE Received | [email protected] |