cbcvebase.
CVE-2026-9800
published 2026-06-25

CVE-2026-9800: A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and…

PriorityP354high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.30%
22.0th percentile
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

Affected

6 ranges
VendorProductVersion rangeFixed in
redhatbuild_of_keycloak>= 26.4 < 26.4.1326.4.13
redhatbuild_of_keycloak26.6 – 26.6.4
rhbkkeycloak-operator-bundle_26.6.4-2
rhbkkeycloak-rhel9
rhbkkeycloak-rhel9-operator_26.6-8
rhbkkeycloak-rhel9_26.6-8

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.