Authentication Vulnerability in Keycloak by Red Hat
CVE-2026-94218
3.1LOW
What is CVE-2026-94218?
A vulnerability in Keycloak's authentication session management allows users to bypass enforced security measures, such as mandatory two-factor authentication (2FA) setup. When administrators implement a stronger authentication flow via client policy, a user can access a specific session restart link that clears the necessary security markers. This enables them to log in simply with their password, circumventing the requirement for 2FA, which poses significant security risks.