In the keycloak-services component for Keycloak in unpatched versions a medium severity vulnerability CVE-2026-79652 was detected. This vulnerability allows an authenticated attacker to bypass user consent requirements and gain unauthorized access. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-79652.
Read more SecurityIn Keycloak in affected versions a medium severity vulnerability CVE-2025-68833 was detected. This vulnerability allows an attacker unauthorized access to resources. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68833.
Read more SecurityIn Keycloak versions prior to the latest patch a medium severity vulnerability CVE-2026-19608 was detected. This vulnerability allows an attacker to potentially bypass group-based access control policies. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19608.
Read more SecurityIn Keycloak a medium severity vulnerability CVE-2026-19608 was detected. This vulnerability allows an attacker to gain unauthorized access to protected resources. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19608.
Read more SecurityIn FreeIPA versions before 4.13.3 a high severity vulnerability CVE-2026-73197 was detected. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by exhausting system memory and disrupting service availability. This occurs due to an unbounded request body read flaw in the /ipa/migration/migration.py endpoint. When processing form POST requests, the migration handler reads the entire, attacker-controlled request body directly into memory without enforcing size limits. By sending oversized requests, an attacker can force excessive memory consumption and severely slow down request handling. There’s no fix available for this issue at the moment. . For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-73197.
In Authentik versions 2026.5.6 and earlier a high severity vulnerability CVE-2026-72534 was detected. This vulnerability allows an attacker to gain superuser privileges. To address this issue, users should upgrade Authentik to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-72534.
Read more SecurityIn OpenWebUI versions 0.8.8 up to 0.11.0 a medium severity vulnerability CVE-2026-70490 was detected. This vulnerability allows an attacker to bypass user verification on terminal routes. To address this issue, users should upgrade OpenWebUI to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-70490.
Read more SecurityIn Wazuh versions prior to 4.14.5 a high severity vulnerability CVE-2026-28220 was detected. This vulnerability allows an authenticated actor to execute arbitrary code on the master node. To address this issue, users should upgrade Wazuh to version 4.14.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28220.
Read more SecurityIn Zeek versions before 8.0.9 a high severity vulnerability CVE-2026-60109 was detected. This vulnerability allows unauthenticated remote attackers to cause a denial of service. To address this issue, users should upgrade Zeek to version 8.0.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60109.
Read more Security