{"ok":true,"trend":{"id":728178,"platform":"mastodon","region":"global","key":"cve-2026-95503 keycloak kerberos auth bypass, cvss 6.8. unpatched. same-network attacker can spoof the kdc and take over","title":"CVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take over","url":"https://mastodon.social/@hugovalters/117371084690274358","first_seen":"2026-10-02T11:31:07.231725Z","last_seen":"2026-10-02T11:31:07.231725Z","last_rank":11,"peak_rank":11,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.6896875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A newly disclosed vulnerability, CVE-2026-95503, affects Keycloak's Kerberos authentication and carries a CVSS score of 6.8. It remains unpatched. An attacker on the same network can spoof the Kerberos Key Distribution Center and take over user accounts. Security commentators urge administrators to isolate Kerberos traffic or stop using password authentication without SPNEGO protection until a fix is released.","why":"Security teams are alerting each other to an unpatched authentication bypass that could allow account takeover in exposed deployments.","tone":"negative","entities":["Keycloak","CVE-2026-95503","Kerberos"],"summarized_at":"2026-10-02T11:32:01.276628Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1136},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Keycloak Kerberos flaw lets network attackers hijack accounts","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T11:31:07.231725Z","rank":11,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@hugovalters/117371084690274358","author":"hugovalters","title":null,"snippet":"CVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take over accounts. Isolate Kerberos or stop using password auth without SPNEGO. https://www. valtersit.com/cve/CVE-2026-955 03/ # CVE # infosec # Keycloak","posted_at":"2026-10-02T11:30:23.327000Z","likes":0}],"elsewhere":[],"window":"7d"}}