Authentication Bypass by Primary Weakness in Red Hat build of Keycloak - CVE-2026-9798
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass brute-force protection for a locked user account.
The vulnerability exists due to improper authentication in the Client-Initiated Backchannel Authentication flow when processing CIBA authentication requests for locked user accounts. A remote attacker can initiate a CIBA authentication request for a locked user account to bypass brute-force protection for a locked user account.
CIBA must be explicitly enabled and configured, and the user must approve the authentication request on their device.