Insufficient verification of data authenticity in Keycloak - CVE-2026-6856
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to bypass acceptable AAGUID policy.
The vulnerability exists due to improper attestation validation in WebAuthn registration when processing packed self-attestation while direct attestation is requested. A remote user can register an authenticator using packed self-attestation to bypass acceptable AAGUID policy.
The AAGUID is unverified when the authenticator does not provide an x5c certificate chain.