Keycloak Client Policies Vulnerability in Keycloak by Red Hat
CVE-2026-9792
6.5MEDIUM
What is CVE-2026-9792?
A vulnerability has been discovered in Keycloak's Client Policies within the org.keycloak.protocol.oidc component. This flaw pertains to specific condition providers such as client-type, client-roles, client-attributes, and client-scopes used to enforce security restrictions. The reject-ropc-grant executor can be bypassed silently, allowing an unauthenticated remote attacker to obtain tokens via the Resource Owner Password Credentials (ROPC) grant, despite having policies intended to block such access. This could lead to unauthorized access to sensitive information.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Evan Hendra (Independent Security Researcher) for reporting this issue.