Comparison using wrong factors in Keycloak - CVE-2026-9800

 

Comparison using wrong factors in Keycloak - CVE-2026-9800

Published: June 29, 2026


Vulnerability identifier: #VU135688
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9800
CWE-ID: CWE-1025
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authorization policies and gain unauthorized access to protected resources.

The vulnerability exists due to comparison using wrong factors in the Keycloak Policy Enforcer when handling request URLs containing the configured access-denied page path. A remote user can include the configured access-denied page path in a request URL as a path segment or query parameter to bypass authorization policies and gain unauthorized access to protected resources.

This can bypass role, scope, and User-Managed Access (UMA) permission checks.


Affected software

Keycloak
Red Hat build of Quarkus

How to mitigate CVE-2026-9800

Install security update from vendor's website.

Keycloak - addressed in versions 26.0.10, 26.6.4
Red Hat build of Quarkus - addressed in versions 3.27.4.SP2, 3.33.2.SP2

External References

Related Security Bulletins