Improper Handling of Insufficient Permissions or Privileges in Keycloak - CVE-2026-9792

 

Improper Handling of Insufficient Permissions or Privileges in Keycloak - CVE-2026-9792

Published: September 5, 2026


Vulnerability identifier: #VU146996
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9792
CWE-ID: CWE-280
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain tokens through a Resource Owner Password Credentials grant.

The vulnerability exists due to improper handling of insufficient permissions or privileges in Keycloak Client Policies within the org.keycloak.protocol.oidc component when processing Resource Owner Password Credentials grant requests with certain condition providers configured. A remote attacker can submit a Resource Owner Password Credentials grant request to obtain tokens through a Resource Owner Password Credentials grant.

Affected condition providers include client-type, client-roles, client-attributes, and client-scopes.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-9792

Install security update from vendor's website.

Keycloak - update to 26.6.3
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3

External References

Related Security Bulletins