Use of Client-Side Authentication in Keycloak - CVE-2026-8830
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to bypass configured WebAuthn policies during credential registration.
The vulnerability exists due to use of client-side authentication in the server-side processAction() when registering a WebAuthn credential. A remote user can manipulate client-side JavaScript to create a credential with parameters that do not match the realm\'s configured WebAuthn policies.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-8830
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3