Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9794

Опубликовано: 28 мая 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

EPSS

Процентиль: 25%
0.00331
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 5.3
redhat
2 месяца назад

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.

CVSS3: 5.3
debian
2 месяца назад

A flaw was found in Keycloak. A remote, unauthenticated attacker can e ...

CVSS3: 5.3
github
2 месяца назад

Keycloak Generates an Error Message Containing Sensitive Information

EPSS

Процентиль: 25%
0.00331
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-209