Authorization Flaw in Keycloak User-Managed Access Implementation
CVE-2026-94217

3.5LOW

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
21 September 2026

What is CVE-2026-94217?

An authorization flaw presents itself within the User-Managed Access (UMA) implementation of Keycloak, specifically at the authorization token endpoint. This issue arises when permission tickets are processed, particularly when different users possess resources with identical names. In such cases, the system erroneously merges permissions, allowing an attacker to gain unauthorized access to resources intended solely for other users. This vulnerability underscores the importance of proper access controls in resource sharing applications.

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.