Insufficient Session Expiration in Keycloak - CVE-2026-9802
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to a victim\'s account.
The vulnerability exists due to insufficient session expiration in Keycloak persistent session handling when revokeRefreshToken=true is enabled, persistent session storage is in use, and the server restarts. A remote attacker can replay a previously captured and revoked refresh token to gain unauthorized access to a victim\'s account.
User interaction is required.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-9802
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3