Flaw in Keycloak Allows Unauthorized Claims Submission in OIDC Flow
CVE-2026-9793
5.9MEDIUM
What is CVE-2026-9793?
A vulnerability in Keycloak allows for the incorrect processing of unsigned claims when handling JWE encrypted request objects. This issue can lead to unauthorized claims being submitted by a remote attacker, potentially compromising data integrity during the OpenID Connect authorization flow. Although a redirect URI allowlist may offer some compensating control, this flaw raises significant concerns regarding adherence to OpenID Connect Core and Financial-grade API signing requirements, making it essential for organizations to review their implementation to avert possible exploitation.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Sree Gopinath (sreelim) for reporting this issue.