Cross-Site Scripting Vulnerability in Keycloak Affects Multiple Users
CVE-2026-9086

7.3HIGH

What is CVE-2026-9086?

A vulnerability has been identified in Keycloak allowing remote attackers with administrative privileges to bypass client URI validation. By registering a malicious client with a specially crafted redirect URI, utilizing a case-insensitive 'javascript:' or 'data:' scheme, attackers can exploit this Cross-Site Scripting vulnerability. This can lead to arbitrary code execution within the Keycloak origin, particularly when victims inadvertently click on malicious links during login or logout processes.

Affected Version(s)

Red Hat build of Keycloak 26.4 26.4.13-1

Red Hat build of Keycloak 26.4 26.4-19

Red Hat build of Keycloak 26.4 26.4-19

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank saku0512 for reporting this issue.
.