CVE-2025-23368High· 8.1▾ TwilightA flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.8%
0.8% → 0.9%
Last analysed / modified upstream
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
wildfly_core < 31.0.3data_grid = 8.0jboss_enterprise_application_platform = 7.0.0jboss_enterprise_application_platform = 8.0.0Upgrade past the affected range:
wildfly_core 31.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak
CVE-2026-15154Medium· 6.5A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI
CVE-2026-16108Medium· 4.3A flaw was found in the default-groups REST endpoint and realm representation of Keycloak
CVE-2026-16106Medium· 4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management
CVE-2026-16104Medium· 4.3A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management