Improper Validation of Specified Quantity in Input in Keycloak - CVE-2026-9704
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper validation of specified quantity in input in the TokenEndpoint when processing an oversized subject_token JSON Web Token (JWT). A remote user can send an oversized subject_token JWT to gain the permissions of the client\'s service account and escalate privileges.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-9704
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3