Medium severity5.3NVD Advisory· Published May 28, 2026· Updated Jun 26, 2026
CVE-2026-9794
CVE-2026-9794
Description
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | <= 26.4.7 | — |
org.keycloak:keycloak-servicesMaven | >= 26.5.0, < 26.6.3 | 26.6.3 |
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
Patches
Vulnerability mechanics
References
14- access.redhat.com/security/cve/CVE-2026-9794nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-fqjh-8322-vgrvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9794ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:25097nvdWEB
- access.redhat.com/errata/RHSA-2026:25098nvdWEB
- access.redhat.com/errata/RHSA-2026:30049nvdWEB
- access.redhat.com/errata/RHSA-2026:30050nvdWEB
- github.com/keycloak/keycloak/commit/05e98366773eec60878bb2a6d5da6bc7048ac3c8ghsaWEB
- github.com/keycloak/keycloak/commit/7750e3ff823d1da8580d42c51194feb2e933b87bghsaWEB
- github.com/keycloak/keycloak/commit/dba79eb03fb9d634fda5e86e1613b8747f968518ghsaWEB
- github.com/keycloak/keycloak/issues/49428ghsaWEB
- github.com/keycloak/keycloak/pull/49684ghsaWEB
- github.com/keycloak/keycloak/pull/49686ghsaWEB
News mentions
1- Keycloak: Twelve Vulnerabilities Disclosed, One High SeverityVypr Intelligence · May 28, 2026