Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74909— Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments

Quick assessment

Affected
Red Hat Red Hat build of Keycloak 26.4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Keycloak 提供策略执行器,通过将传入的 Web 请求与已定义的安全策略进行匹配,来保护应用程序。发现存在一个漏洞:当 Web 地址中包含特殊编码字符(例如代表分号或目录遍历段落的字符)时,策略执行器无法正确地对 Web 地址进行规范化处理。经过身份验证的用户可以利用这些编码字符,诱使策略执行器应用比预期更宽松的安全策略,从而可能获得对敏感的管理端点或私有应用程序端点的未授权访问。

CVSS 8.1 · High

Possible ATT&CK Techniques 1 AI

T1071.001 · Web Protocols
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-74909

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments
Source: CVE Program / CVE List V5
Vulnerability Description
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat build of Keycloak 26.4 26.4-26 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4 26.4-26 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4 26.4.16-2 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4.16 - cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4.16 - cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.6 26.6-20 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6 26.6.7-3 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6 26.6-20 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.7 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.7 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-74909

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74909

登录查看更多情报信息。

Vendor Advisories for CVE-2026-74909 (1)

Other References for CVE-2026-74909 (5)

Same Patch Batch · Red Hat · 2026-09-16 · 9 CVEs total

CVE-2026-79651 7.5 HIGH Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching
CVE-2026-18212 7.5 HIGH Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state
CVE-2026-42784 7.4 HIGH Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio
CVE-2026-17526 7.2 HIGH Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t
CVE-2026-92615 6.6 MEDIUM Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena
CVE-2026-92358 6.4 MEDIUM Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil
CVE-2026-92091 5.9 MEDIUM Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops
CVE-2026-19607 5.3 MEDIUM Keycloak-services: keycloak-services: broker-originated username collision causes account

IV. Related Vulnerabilities

V. Comments for CVE-2026-74909

No comments yet


Leave a comment