Pushed Authorization Request Flaw in Keycloak Allows Authorization Code Reuse
CVE-2026-96446

4.2MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96446?

A flaw exists in the Pushed Authorization Request (PAR) implementation of Keycloak that impacts the silent authentication process using prompt=none. This vulnerability allows attackers to bypass essential security steps if a user is already authenticated. As a result, the application fails to enforce a critical security rule that a pushed request URI is utilized only once. Attackers may exploit this weakness to reuse a request URI and potentially acquire multiple authorization codes for signed-in users, infringing upon established security standards like FAPI-2.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.