Medium severity5.9NVD Advisory· Published May 28, 2026· Updated Aug 20, 2026
CVE-2026-9793
CVE-2026-9793
Description
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | <= 26.6.4 | — |
Affected products
10(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
- osv-coords7 versionspkg:apk/chainguard/keycloak-26.6pkg:apk/chainguard/keycloak-26.6-iamguarded-compatpkg:apk/chainguard/keycloak-fips-26.6pkg:apk/chainguard/keycloak-fips-26.6-iamguarded-fipspkg:apk/chainguard/request-9047-keycloak-fips-26.6-iamguarded-fipspkg:apk/wolfi/keycloak-26.6pkg:apk/wolfi/keycloak-26.6-iamguarded-compat
< 26.6.6-r0+ 6 more
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
Patches
Vulnerability mechanics
References
9- access.redhat.com/security/cve/CVE-2026-9793nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-p3v8-fm5p-v84hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9793ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:50846nvdWEB
- access.redhat.com/errata/RHSA-2026:50847nvdWEB
- access.redhat.com/errata/RHSA-2026:50848nvdWEB
- access.redhat.com/errata/RHSA-2026:50849nvdWEB
- github.com/keycloak/keycloak/issues/49429ghsaWEB
News mentions
1- Keycloak: Twelve Vulnerabilities Disclosed, One High SeverityVypr Intelligence · May 28, 2026