CLEANSTART-2026-RY77599

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RY77599.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-RY77599
Upstream
  • CVE-2026-18214
Published
2026-09-19T00:41:29Z
Modified
2026-09-19T01:00:07Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains
Details

Security vulnerability affects the keycloak package. Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains.

References

Affected packages

CleanStart / keycloak

Package

Name
keycloak

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.7.2-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RY77599.json"