Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9800

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
Версия от 26.4 (включая) до 26.4.13 (исключая)
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
Версия от 26.6 (включая) до 26.6.4 (включая)

EPSS

Процентиль: 22%
0.00303
Низкий

8.1 High

CVSS3

Дефекты

CWE-1025
CWE-1025

Связанные уязвимости

CVSS3: 8.1
redhat
2 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

CVSS3: 8.1
debian
около 1 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allow ...

CVSS3: 8.1
github
около 1 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

EPSS

Процентиль: 22%
0.00303
Низкий

8.1 High

CVSS3

Дефекты

CWE-1025
CWE-1025