Information Exposure Through an Error Message in Keycloak - CVE-2026-9794

 

Information Exposure Through an Error Message in Keycloak - CVE-2026-9794

Published: July 1, 2026 / Updated: September 5, 2026


Vulnerability identifier: #VU146983
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9794
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose client protocol information.

The vulnerability exists due to generation of error messages containing sensitive information in the SAML ECP endpoint when handling specially crafted SOAP requests with varying client IDs. A remote attacker can observe distinct faultstrings in responses to determine a client\'s protocol type and disclose client protocol information.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-9794

Install security update from vendor's website.

Keycloak - update to 26.6.3
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3

External References

Related Security Bulletins