Medium severity6.5NVD Advisory· Published May 28, 2026· Updated Jun 26, 2026
CVE-2026-9792
CVE-2026-9792
Description
A flaw was found in Keycloak's Client Policies, specifically within the org.keycloak.protocol.oidc component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the reject-ropc-grant executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password Credentials (ROPC) grant, even when a policy is explicitly configured to block it. This bypass can lead to unauthorized access and information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | >= 26.5.0, < 26.6.3 | 26.6.3 |
org.keycloak:keycloak-servicesMaven | <= 26.4.7 | — |
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
Patches
Vulnerability mechanics
References
14- access.redhat.com/security/cve/CVE-2026-9792nvdMitigationVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-33j3-g875-37rpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9792ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:25097nvdWEB
- access.redhat.com/errata/RHSA-2026:25098nvdWEB
- access.redhat.com/errata/RHSA-2026:30049nvdWEB
- access.redhat.com/errata/RHSA-2026:30050nvdWEB
- github.com/keycloak/keycloak/commit/13622ee0ffed91fd07ef444be2c858a7f356766dghsaWEB
- github.com/keycloak/keycloak/commit/2af73c16a4e49333779bb34bce65461d9af036a4ghsaWEB
- github.com/keycloak/keycloak/commit/af5e3e8c60842bc1f3a78e6be414fe303f93163dghsaWEB
- github.com/keycloak/keycloak/issues/49436ghsaWEB
- github.com/keycloak/keycloak/pull/49636ghsaWEB
- github.com/keycloak/keycloak/pull/49637ghsaWEB
News mentions
1- Keycloak: Twelve Vulnerabilities Disclosed, One High SeverityVypr Intelligence · May 28, 2026