Kerberos Authentication Flaw in Keycloak Affects User Identity Verification
CVE-2026-95503

6.8MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
22 September 2026

What is CVE-2026-95503?

A significant flaw exists within the Kerberos federation provider of Keycloak, which is a widely used open-source identity and access management tool. This vulnerability arises when Kerberos password authentication is utilized without the SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism) protocol. The flaw occurs because the system does not adequately verify the identity of the Key Distribution Center (KDC). Consequently, this allows malicious actors on the same network to potentially impersonate the KDC, thereby circumventing the authentication process and gaining unauthorized access to user accounts.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Leo Jianze (lijianze98@gmail.com) for reporting this issue.
.