Access Control Bypass Affecting org.keycloak:keycloak-ldap-federation package, versions [,26.4.14)[26.6.0, 26.6.5)[26.7.0, 26.7.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-18751969
  • published13 Aug 2026
  • disclosed5 Aug 2026
  • creditUnknown

Introduced: 5 Aug 2026

NewCVE-2026-16071  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade org.keycloak:keycloak-ldap-federation to version 26.4.14, 26.6.5, 26.7.1 or higher.

Overview

Affected versions of this package are vulnerable to Access Control Bypass in LDAPStorageProvider.searchLDAPByAttributes through LDAP_ENTRY_DN lookups in federation/ldap/src/main/java/org/keycloak/storage/ldap/LDAPStorageProvider.java. A delegated administrator can retrieve and import directory entries outside the configured usersDn by sending a search request with a crafted q=LDAP_ENTRY_DN:<dn> value. This exposes account information from unauthorized parts of the LDAP directory and can cause those out-of-scope users to be imported into local storage.

CVSS Base Scores

version 4.0
version 3.1