Flaw in Keycloak Allows Unauthorized Claims Submission in OIDC Flow
CVE-2026-9793

5.9MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
28 May 2026

What is CVE-2026-9793?

A vulnerability in Keycloak allows for the incorrect processing of unsigned claims when handling JWE encrypted request objects. This issue can lead to unauthorized claims being submitted by a remote attacker, potentially compromising data integrity during the OpenID Connect authorization flow. Although a redirect URI allowlist may offer some compensating control, this flaw raises significant concerns regarding adherence to OpenID Connect Core and Financial-grade API signing requirements, making it essential for organizations to review their implementation to avert possible exploitation.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Sree Gopinath (sreelim) for reporting this issue.
.