Medium severity4.3NVD Advisory· Published May 28, 2026· Updated Aug 20, 2026
CVE-2026-9798
CVE-2026-9798
Description
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | <= 26.4.7 | — |
org.keycloak:keycloak-servicesMaven | >= 26.5.0, <= 26.6.4 | — |
Affected products
10(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
- osv-coords7 versionspkg:apk/chainguard/keycloak-26.6pkg:apk/chainguard/keycloak-26.6-iamguarded-compatpkg:apk/chainguard/keycloak-fips-26.6pkg:apk/chainguard/keycloak-fips-26.6-iamguarded-fipspkg:apk/chainguard/request-9047-keycloak-fips-26.6-iamguarded-fipspkg:apk/wolfi/keycloak-26.6pkg:apk/wolfi/keycloak-26.6-iamguarded-compat
< 26.6.6-r0+ 6 more
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
- (no CPE)range: < 26.6.6-r0
Patches
Vulnerability mechanics
References
15- access.redhat.com/security/cve/CVE-2026-9798nvdMitigationVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-q6h7-xxp7-7429ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9798ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:50846nvdWEB
- access.redhat.com/errata/RHSA-2026:50847nvdWEB
- access.redhat.com/errata/RHSA-2026:50848nvdWEB
- access.redhat.com/errata/RHSA-2026:50849nvdWEB
- github.com/keycloak/keycloak/commit/11c2695064cd93da1d333df3f69d4a4141e86c29ghsaWEB
- github.com/keycloak/keycloak/commit/2edc6b112e2dedce63062b89ab3c7ae542e0d9acghsaWEB
- github.com/keycloak/keycloak/commit/a11e3254efc16ae72ce5092b93b9f557a4ba43aeghsaWEB
- github.com/keycloak/keycloak/issues/49432ghsaWEB
- github.com/keycloak/keycloak/pull/49791ghsaWEB
- github.com/keycloak/keycloak/pull/49903ghsaWEB
- github.com/keycloak/keycloak/pull/49905ghsaWEB
News mentions
1- Keycloak: Twelve Vulnerabilities Disclosed, One High SeverityVypr Intelligence · May 28, 2026