What is CVE-2026-16071?
A flaw was found in Keycloak's LDAP storage provider used for federating user identities. When a delegated administrator searches with a specific LDAP entry Distinguished Name (DN), missing validation allows unauthorized lookups. This can compromise authentication and identity federation mechanisms.
Azərbaycanca: Keycloak-ın LDAP storage provider komponentində zəiflik aşkarlanıb. Təyin edilmiş administrator xüsusi Distinguished Name (DN) ilə axtarış etdikdə, yetərsiz validasiya səbəbindən icazəsiz lookup əməliyyatları baş verə bilər. Bu, autentifikasiya və identifikasiya mexanizmlərini riskə ata bilər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which component in Keycloak is affected by CVE-2026-16071?
The vulnerability was found in Keycloak's LDAP storage provider component.
Why does a threat arise when searching with a specific LDAP DN in Keycloak?
Missing validation allows unauthorized lookups to occur.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.