CVE-2025-12150
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation p
CVSS
3.1
Low
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Published: Feb 27, 2026 · Last modified: Aug 10, 2026 · CWE-347
0.2%EPSS · 30 days0.2%
2026-07-152026-08-12
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:21370
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:21371
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:22088
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:22089
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2025-12150
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2406192
- github.comhttps://github.com/keycloak/keycloak/issues/43723
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-122638.8 HIG—
——0Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.2hCVE-2026-487912.0 LOW—
——0sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verification with enhancements that adhere to the Sigstore verification spec. The old sigstore-conformance test for this check was built incorrectly. This vulnerability impacts only users verifying bundles with `dev.sigstore:sigstore-java:2.0.0`. Older versions are not affected; it is fixed in `dev.sigstore:sigstore-java:2.1.0` A malicious actor may exploit this if they were able to access a users system and exfiltrate the temporary private key used during signing and then reuse an old fulcio certificate later without requiring direct access to the user's credentials. Users may protect themselves by re-verifying their artifacts using the newest sigstore-java or another current sigstore client. Transparency logs may also be audited for unauthorized signatures for a suspected reused identity.13hCVE-2026-687597.2 HIG—
——0A holder of a valid integration credential may impersonate other users under specific conditions.18hCVE-2026-687577.5 HIG—
——0A user with access to a valid SAML response may impersonate another user under specific conditions.17hCVE-2026-627575.3 MED16.2%
——5Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.22hCVE-2026-155568.1 HIG11.5%
——3A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.21h