Improper Handling of Insufficient Permissions or Privileges in Keycloak - CVE-2026-9792
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to obtain tokens through a Resource Owner Password Credentials grant.
The vulnerability exists due to improper handling of insufficient permissions or privileges in Keycloak Client Policies within the org.keycloak.protocol.oidc component when processing Resource Owner Password Credentials grant requests with certain condition providers configured. A remote attacker can submit a Resource Owner Password Credentials grant request to obtain tokens through a Resource Owner Password Credentials grant.
Affected condition providers include client-type, client-roles, client-attributes, and client-scopes.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-9792
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3