PT-2026-20651 · Docker+1 · Docker+1

Published

2026-02-19

·

Updated

2026-03-05

·

CVE-2026-2733

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the Docker v2 authentication endpoint of Keycloak where authentication tokens remain valid even after a Docker registry client has been administratively disabled. Specifically, toggling the client’s “Enabled” setting to OFF does not completely block access. Consequently, previously valid credentials can still be used to obtain authentication tokens, potentially weakening administrative controls and allowing unintended access to container registry resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-2733
GHSA-FJF4-6F34-W64Q

Affected Products

Docker
Keycloak