Authentication Bypass Vulnerability in Keycloak Identity Management System
CVE-2026-9798

4.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
28 May 2026

What is CVE-2026-9798?

A vulnerability exists in Keycloak's Client-Initiated Backchannel Authentication (CIBA) flow, where an attacker with valid client credentials can exploit a flaw that bypasses brute-force protections for temporarily locked accounts. This loophole allows unauthorized users to continue authentication attempts and issue tokens even during lockout periods, potentially leading to further unauthorized access and exploitation of accounts.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Evan Hendra (Independent Security Researcher) for reporting this issue.
.