LDAP Storage Provider Flaw in Keycloak Affects User Identity Federation
CVE-2026-16071
5.4MEDIUM
What is CVE-2026-16071?
An identified flaw in the LDAP storage provider of Keycloak allows delegated administrators to perform searches using specific LDAP entry Distinguished Names (DN). Due to insufficient validation, this vulnerability permits lookups for users beyond the established search boundaries, leading to unintentional disclosure of account information from unauthorized sections of the directory. Consequently, this can result in the unintended importing of these users into local storage, thus compromising user data integrity and privacy.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.