VYPR
Medium severity6.5NVD Advisory· Published May 28, 2026· Updated Jun 26, 2026

CVE-2026-9792

CVE-2026-9792

Description

A flaw was found in Keycloak's Client Policies, specifically within the org.keycloak.protocol.oidc component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the reject-ropc-grant executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password Credentials (ROPC) grant, even when a policy is explicitly configured to block it. This bypass can lead to unauthorized access and information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.keycloak:keycloak-servicesMaven
>= 26.5.0, < 26.6.326.6.3
org.keycloak:keycloak-servicesMaven
<= 26.4.7

Affected products

3

Patches

Vulnerability mechanics

References

14

News mentions

1