VYPR
advisoryPublished Sep 24, 2026· 1 source

Keycloak: 15 Vulnerabilities Disclosed, Including 4 High-Severity Flaws

Key findings • 15 Keycloak vulnerabilities disclosed between Sept 16-24, 2026, including 4 high-severity flaws. • High-severity issues include policy enforcer bypass, SAML binding memory leak…

Key findings

  • 15 Keycloak vulnerabilities disclosed between Sept 16-24, 2026, including 4 high-severity flaws.
  • High-severity issues include policy enforcer bypass, SAML binding memory leaks, and admin impersonation.
  • Medium-severity flaws impact Admin API, authentication, authorization, and OIDC protocol implementations.
  • Low-severity vulnerabilities involve bypasses of 2FA setup and UMA permission handling.
  • The batch highlights risks across Keycloak's authentication, authorization, and administrative functions.

On September 16, 2026, a significant batch of 15 vulnerabilities was disclosed for Keycloak, the open-source identity and access management solution. These vulnerabilities, disclosed over an eight-day period, span a range of severities, including four high-severity flaws, impacting various components of the Keycloak platform. The disclosures highlight potential weaknesses in authentication, authorization, session management, and protocol implementations.

Several high-severity vulnerabilities were detailed in this batch. CVE-2026-74909, with a CVSSv3 score of 8.1, stems from the policy enforcer's failure to correctly normalize web addresses containing special encoded characters, potentially allowing attackers to bypass security policies. CVE-2026-18212 (CVSSv3 7.5) impacts the SAML Redirect Binding implementation due to improper memory management in DEFLATE compression and decompression helpers, which could be exploited by unauthenticated attackers. Additionally, CVE-2026-17526 (CVSSv3 7.2) allows a user with impersonation roles to impersonate a realm administrator, granting them full administrative control. Finally, CVE-2026-90997 (CVSSv3 7.4) presents a bypass of replay protection when Keycloak is deployed in stateless mode with MySQL or MariaDB, enabling attackers to exploit intercepted security artifacts.

Medium-severity issues also emerged across different functional areas. CVE-2026-97176 and CVE-2026-96446 both relate to authentication enforcement and Pushed Authorization Request (PAR) implementations, respectively, with CVSSv3 scores of 4.2. CVE-2026-95503 (CVSSv3 6.8) affects the Kerberos federation provider, allowing potential impersonation of the Key Distribution Center (KDC) when SPNEGO is not used. The Admin REST API is implicated in multiple vulnerabilities, including CVE-2026-94215 (CVSSv3 5.5), where a cache resolution flaw allows client access across realms, and CVE-2026-94001 (CVSSv3 6.5), where a delegated administrator can delete user credentials without proper permission checks. CVE-2026-94000 (CVSSv3 6.6) also affects the Admin REST API, specifically group-membership endpoints, allowing unauthorized privilege escalation. Other medium-severity flaws include issues in authorization services (CVE-2026-94213, CVSSv3 4.9), OIDC token refresh (CVE-2026-93999, CVSSv3 4.2), and first broker login flows (CVE-2026-92358, CVSSv3 6.4).

Low-severity vulnerabilities were also part of this disclosure. CVE-2026-94218 (CVSSv3 3.1) details a bypass of administrator-enforced two-factor authentication setup through client policies. CVE-2026-94217 (CVSSv3 3.5) involves incorrect permission merging in the User-Managed Access (UMA) implementation when resource names are duplicated.

The broad range of vulnerabilities disclosed together underscores the importance of regular security audits and timely patching for Keycloak deployments. Users are advised to consult the official Keycloak security advisories for specific version information and recommended mitigation steps. The coordinated disclosure of these numerous flaws highlights a significant security event for the Keycloak ecosystem, emphasizing the need for vigilance in managing identity and access control.

This batch of vulnerabilities affects multiple aspects of Keycloak's functionality, from core authentication mechanisms to administrative interfaces and specific protocol implementations. The presence of high-severity flaws, particularly those related to administrative control and policy enforcement, necessitates prompt attention from administrators.

The disclosures span various components, including authentication enforcement, Pushed Authorization Requests, Kerberos federation, session management, User-Managed Access (UMA), Admin REST API, Authorization Services, OIDC protocol, SAML binding, and policy enforcement.

The vulnerabilities were disclosed between September 16 and September 24, 2026. The specific versions of Keycloak affected by each vulnerability are detailed in the respective CVE advisories. Users should refer to these advisories for precise patching information.

The impact of these vulnerabilities ranges from potential bypass of security policies and authentication flows to full administrative takeover of realms, depending on the specific CVE. The coordinated nature of this disclosure suggests a comprehensive review of Keycloak's security posture.

Keycloak users should prioritize updating their instances to patched versions as soon as possible, paying close attention to the high-severity vulnerabilities that pose the most immediate risk. Staying informed about future security advisories from the Keycloak project is crucial for maintaining a secure environment.

Synthesized by Vypr AI
Keycloak: 15 Vulnerabilities Disclosed, Including 4 High-Severity Flaws · VYPR