CVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-25 17:17

Updated : 2026-09-14 13:19


NVD link : CVE-2026-9800

Mitre link : CVE-2026-9800

CVE.ORG link : CVE-2026-9800


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-1025

Comparison Using Wrong Factors