Loading
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.
Use CWE-601, Redhat vendor hub and Build Of Keycloak product page to widen CVE-2026-3872 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-4636, CVE-2026-4634 and CVE-2026-4282 for nearby disclosures in the same product family.