Update your Keycloak
For community, version 26.7.2 has the fix:
www.keycloak.org/2026/08/keycloak-2672-released
Submitted 2 days ago by
exu@feditown.com to selfhosted@lemmy.world
https://access.redhat.com/security/cve/cve-2026-18963
Update your Keycloak
For community, version 26.7.2 has the fix:
www.keycloak.org/2026/08/keycloak-2672-released
This one is bad - unauthenticated user account take over.
If you’re like me and only using it internally on a homelab, the risks are lessened, but if you expose keycloak to by the Internet - boy howdy
iamthetot@piefed.ca 2 days ago
Out of curiosity, what is the advantage of using something like this on LAN only?
Dunstabzugshaubitze@feddit.org 2 days ago
for many people homelabbing is a way to gain knowledge they can use on the job.
other than that: proper single sign on across your services is nice even if you don’t expose them to anybody else.
For me, I have multiple OIDC compatible systems (Proxmox, Netbox, Synology, Zabbix, Vault, etc).
So keycloak offers a SSO option to make my life easier with a single account to worry about instead of individual ones.
Plus MFA because it’s cool?
possiblylinux127@lemmy.zip 2 days ago
Not being impacted by security issues like these for one
B0rax@feddit.org 2 days ago
It will still sync to all devices. And if you have an always on vpn to your home network, there really is no need to expose it to the public
NarrativeBear@lemmy.world 1 day ago
When you host something on LAN only you are not exposing the service to the wider internet.
This means someone would need access to your LAN or local area network first (such as your WiFi password) before being able to reach said service.
Now when you expose something directly to the internet, in a way that it displays a publicly accessible webpage it makes it easier for anyone to reach that webpage and potentially figure out your login and password information through brute force. Or some type exploit that allows full bypass of the login credentials.
Some self-hosters choose to keep their more sensitive services on the LAN only and then use a VPN (that’s hosted privately) to access their LAN remotely from anywhere in the world.
With a VPN hosted on your LAN it provides a good layer of security as someone would first need to have access to your VPN to then potentially try and get access into your services.
Especially in an enterprise environment where plenty of people use
first.lastname@company