Medium severity4.2NVD Advisory· Published May 27, 2026· Updated Aug 20, 2026
CVE-2026-9689
CVE-2026-9689
Description
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | >= 26.5.0, <= 26.6.4 | — |
org.keycloak:keycloak-servicesMaven | <= 26.4.7 | — |
Affected products
11(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
- osv-coords8 versionspkg:apk/chainguard/keycloak-26.6pkg:apk/chainguard/keycloak-26.6-iamguarded-compatpkg:apk/chainguard/keycloak-fips-26.6pkg:apk/chainguard/keycloak-fips-26.6-iamguarded-fipspkg:apk/chainguard/request-9047-keycloak-fips-26.6pkg:apk/chainguard/request-9047-keycloak-fips-26.6-iamguarded-fipspkg:apk/wolfi/keycloak-26.6pkg:apk/wolfi/keycloak-26.6-iamguarded-compat
< 26.6.6-r0+ 7 more
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
Patches
Vulnerability mechanics
References
13- access.redhat.com/security/cve/CVE-2026-9689nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-wcvj-vpvw-9rr5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9689ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:50846nvdWEB
- access.redhat.com/errata/RHSA-2026:50847nvdWEB
- access.redhat.com/errata/RHSA-2026:50848nvdWEB
- access.redhat.com/errata/RHSA-2026:50849nvdWEB
- github.com/keycloak/keycloak/commit/18832bcae5bebd5a1d66c2ec5fcd640e576fa625ghsaWEB
- github.com/keycloak/keycloak/commit/1f58a4b79a258bcf2ef86b58fbf0016cdb91291fghsaWEB
- github.com/keycloak/keycloak/commit/267a1a33d4dc1eac7622614ba9772b4e1e35726fghsaWEB
- github.com/keycloak/keycloak/issues/49430ghsaWEB
- github.com/keycloak/keycloak/pull/49959ghsaWEB
News mentions
1- Keycloak: Twelve Vulnerabilities Disclosed, One High SeverityVypr Intelligence · May 28, 2026