Information Exposure Through an Error Message in Keycloak - CVE-2026-9794
Published: July 1, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose client protocol information.
The vulnerability exists due to generation of error messages containing sensitive information in the SAML ECP endpoint when handling specially crafted SOAP requests with varying client IDs. A remote attacker can observe distinct faultstrings in responses to determine a client\'s protocol type and disclose client protocol information.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-9794
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3