Improper Verification of Cryptographic Signature in Red Hat build of Keycloak - CVE-2026-9793
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to submit unauthorized claims in the OIDC authorization flow.
The vulnerability exists due to improper verification of cryptographic signatures in JWE-encrypted request object processing when processing a JWE-encrypted request object with raw JSON plaintext. A remote attacker can submit a JWE-encrypted request object with raw JSON plaintext to submit unauthorized claims in the OIDC authorization flow.