๐Ÿ” CVE Alert

CVE-2026-9799

MEDIUM 4.6

Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass

CVSS Score
4.6
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even if they do not have a ticket for those specific resources. This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, where no explicit policy protects the resource type. The primary consequence is unauthorized information disclosure or modification of resources.

CWE CWE-639
Vendor red hat
Product red hat build of keycloak 26.6
Published Jun 25, 2026
Last Updated Jun 26, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak 26.6

Be the first to know when new medium vulnerabilities affecting red hat red hat build of keycloak 26.6 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6.4
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:30083 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:30084 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-9799 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2482471

Credits

Red Hat would like to thank Omaroo Baniessa for reporting this issue.