Keycloak Client Policies Vulnerability in Keycloak by Red Hat
CVE-2026-9792

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
28 May 2026

What is CVE-2026-9792?

A vulnerability has been discovered in Keycloak's Client Policies within the org.keycloak.protocol.oidc component. This flaw pertains to specific condition providers such as client-type, client-roles, client-attributes, and client-scopes used to enforce security restrictions. The reject-ropc-grant executor can be bypassed silently, allowing an unauthenticated remote attacker to obtain tokens via the Resource Owner Password Credentials (ROPC) grant, despite having policies intended to block such access. This could lead to unauthorized access to sensitive information.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Evan Hendra (Independent Security Researcher) for reporting this issue.
.