HTTP Parameter Pollution Vulnerability in Keycloak Identity Solution
CVE-2026-9689
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-9689?
A flaw in Keycloak, an open-source identity and access management solution, allows remote attackers to exploit the authentication process by crafting deceptive web addresses. When client applications are configured to accept broad redirect URIs, attackers can influence the prioritization of information during an authentication attempt. This may lead to unauthorized access to resources, as legitimate data may be overshadowed by attacker-controlled information. Organizations using Keycloak should assess their configuration to mitigate the risk of exploitation through this vulnerability.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.14-1
Red Hat build of Keycloak 26.4 26.4-22
Red Hat build of Keycloak 26.4 26.4-22
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved