Security Flaw in Keycloak Affecting Authentication Mechanism
CVE-2026-96445
6.8MEDIUM
What is CVE-2026-96445?
A security vulnerability has been identified in Keycloak's Conditional OTP authenticator that could compromise user accounts. The flaw arises when the system evaluates specific HTTP headers to determine whether to skip the one-time password (OTP) authentication step. However, the application does not verify the legitimacy of these headers, making it possible for an attacker with a user's password to bypass the OTP process entirely by sending a crafted HTTP header. This situation presents a serious risk to user accounts and the overall security of the Keycloak implementation.
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits in collaboration with OpenAI) for reporting this issue.