VYPR

keycloak policy enforcer

by Keycloak

CVEs (1)

  • CVE-2026-9800Jun 25, 2026
    risk 0.00cvss epss 0.00

    A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL,…