CVE-2026-1518
EUVD-2026-513002.02.2026, 08:16
A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services.
Awaiting analysis
This vulnerability is currently awaiting analysis.