Authentication Bypass by Primary Weakness in Red Hat build of Keycloak - CVE-2026-9798

 

Authentication Bypass by Primary Weakness in Red Hat build of Keycloak - CVE-2026-9798

Published: September 11, 2026


Vulnerability identifier: #VU148993
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9798
CWE-ID: CWE-305
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass brute-force protection for a locked user account.

The vulnerability exists due to improper authentication in the Client-Initiated Backchannel Authentication flow when processing CIBA authentication requests for locked user accounts. A remote attacker can initiate a CIBA authentication request for a locked user account to bypass brute-force protection for a locked user account.

CIBA must be explicitly enabled and configured, and the user must approve the authentication request on their device.


Affected software

Red Hat build of Keycloak

How to mitigate CVE-2026-9798

Install security update from vendor's website.

Red Hat build of Keycloak - update to 26.6.5

External References

Related Security Bulletins