Medium severity6.5NVD Advisory· Published Jun 25, 2026· Updated Jul 1, 2026
CVE-2026-9705
CVE-2026-9705
Description
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.
Affected products
2Patches
Vulnerability mechanics
References
6- access.redhat.com/errata/RHSA-2026:30049nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:30050nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:30083nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:30084nvdVendor Advisory
- access.redhat.com/security/cve/CVE-2026-9705nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdVendor Advisory
News mentions
0No linked articles in our index yet.