Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9799— Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass

CVSS 4.6 · Medium EPSS 0.17% · P6

Affected Version Matrix 8

VendorProductVersion RangeStatus
Red HatRed Hat build of Keycloak 26.426.4.13-1< *unaffected
26.4-19< *unaffected
26.4-19< *unaffected
Red HatRed Hat build of Keycloak 26.4.13anyunaffected
Red HatRed Hat build of Keycloak 26.626.6.4-2< *unaffected
26.6-8< *unaffected
26.6-8< *unaffected
Red HatRed Hat build of Keycloak 26.6.4anyunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9799

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even if they do not have a ticket for those specific resources. This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, where no explicit policy protects the resource type. The primary consequence is unauthorized information disclosure or modification of resources.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5
Vulnerability Title
Keycloak 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Keycloak是Keycloak组织开源的一种开源身份和访问管理解决方案。 Keycloak存在授权问题漏洞,该漏洞源于用户管理访问授权中的访问控制问题,可能导致通过特定权限请求前缀绕过按资源访问控制,从而未经授权访问同一资源服务器内的所有资源。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat build of Keycloak 26.4 26.4.13-1 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-19 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-19 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4.13-cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.6 26.6.4-2 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-8 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-8 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.4-cpe:/a:redhat:build_keycloak:26.6::el9

II. Public POCs for CVE-2026-9799

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9799

登录查看更多情报信息。

Vendor Advisories for CVE-2026-9799 (1)

Other References for CVE-2026-9799 (5)

Same Patch Batch · Red Hat · 2026-06-25 · 13 CVEs total

CVE-2026-129758.5 HIGHApicurio/apicurio-registry: apicurio-registry: unhardened saxparser in content-type detect
CVE-2026-98008.1 HIGHKeycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri
CVE-2026-118008.1 HIGHOrg.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusio
CVE-2026-90997.7 HIGHKeycloak: group-admin escalation to realm-admin
CVE-2026-129927.4 HIGHApicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl
CVE-2026-90867.3 HIGHKeycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
CVE-2026-130836.9 MEDIUMPen-drive: pen-drive: stored xss via unescaped cluster data in html report
CVE-2026-97056.5 MEDIUMKeycloak: keycloak: attacker can re-enable and take over disabled clients via registration
CVE-2026-129936.5 MEDIUMApicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via
CVE-2026-133186.4 MEDIUMVirt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-ag
CVE-2026-90834.9 MEDIUMKeycloak: keycloak: information disclosure through arbitrary filesystem path probing
CVE-2026-132184.2 MEDIUMKubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from

IV. Related Vulnerabilities

V. Comments for CVE-2026-9799

No comments yet


Leave a comment