Security Flaw in Keycloak Affecting Authentication Mechanism
CVE-2026-96445

6.8MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96445?

A security vulnerability has been identified in Keycloak's Conditional OTP authenticator that could compromise user accounts. The flaw arises when the system evaluates specific HTTP headers to determine whether to skip the one-time password (OTP) authentication step. However, the application does not verify the legitimacy of these headers, making it possible for an attacker with a user's password to bypass the OTP process entirely by sending a crafted HTTP header. This situation presents a serious risk to user accounts and the overall security of the Keycloak implementation.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits in collaboration with OpenAI) for reporting this issue.
.