VDB

CVE-2025-10939

CVE-2025-10939 PUBLISHED CVSS 3.700000047683716 LOW

Keycloak unable to restrict access to the admin console

EPSS 0.01% · 2.8th percentile

Risk Scores

CVSS v3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.01%
2.8th percentile

Affected Products

VendorProductVersions
Red HatRed Hat build of Keycloak 26.4.4
Keycloakkeycloak0
Mavenorg.keycloak:keycloak-quarkus-server0
Red HatRed Hat build of Keycloak 26.426.4.4-1
Red HatRed Hat build of Keycloak 26.426.4-3
Red HatRed Hat build of Keycloak 26.426.4-3

Timeline

  • Sep 25, 2025 CVE ID Reserved
  • Oct 28, 2025 EPSS Score
  • Oct 28, 2025 Coalition ESS Score
  • Oct 28, 2025 CVE Published
  • Oct 28, 2025 PoC Published
  • Oct 30, 2025 Coalition ESS Score
  • Nov 3, 2025 EPSS Score
  • Nov 4, 2025 Coalition ESS Score
  • Nov 8, 2025 EPSS Score
  • Nov 14, 2025 EPSS Score
  • Nov 14, 2025 Coalition ESS Score
  • Nov 16, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›