CVE-2026-9800
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.63%
- CWE
- CWE-1025
- Published
- 2026-06-25
- Last modified
- 2026-08-06
Affected products
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.4
- Red Hat Red Hat build of Keycloak 26.4
- Red Hat Red Hat build of Keycloak 26.4
- Red Hat Red Hat build of Keycloak 26.4
Weakness type
Related vulnerabilities
- CVE-2023-54390 — PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2026-75840 — ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
- CVE-2025-71377 — stoatchat before 20250210-1 Unrestricted Message History Fetch
- CVE-2026-48860 — Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
- CVE-2026-40880 — Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
- CVE-2026-40227 — In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with...
- CVE-2026-21691 — iccDEV has Type Confusion in CIccTag:IsTypeCompressed()