Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.
References
Configurations
No configuration.
History
16 Sep 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Sep 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 15:17
Updated : 2026-09-16 19:42
NVD link : CVE-2026-74909
Mitre link : CVE-2026-74909
CVE.ORG link : CVE-2026-74909
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
