Flaw in Keycloak Allows Unauthorized Claims Submission in OIDC Flow
CVE-2026-9793
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 28 May 2026
What is CVE-2026-9793?
A vulnerability in Keycloak allows for the incorrect processing of unsigned claims when handling JWE encrypted request objects. This issue can lead to unauthorized claims being submitted by a remote attacker, potentially compromising data integrity during the OpenID Connect authorization flow. Although a redirect URI allowlist may offer some compensating control, this flaw raises significant concerns regarding adherence to OpenID Connect Core and Financial-grade API signing requirements, making it essential for organizations to review their implementation to avert possible exploitation.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.14-1
Red Hat build of Keycloak 26.4 26.4-22
Red Hat build of Keycloak 26.4 26.4-22
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved