Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9800

Опубликовано: 19 мая 2026
Источник: redhat
CVSS3: 8.1

Описание

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkuskeycloak-policy-enforcerOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-policy-enforcerAffected
Red Hat Satellite 6candlepinUnder investigation
Red Hat Satellite 6satellite:el8/candlepinUnder investigation
Red Hat Single Sign-On 7servlet-policy-enforcerOut of support scope
Red Hat build of Keycloak 26.4rhbk/keycloak-operator-bundleFixedRHSA-2026:3005025.06.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9FixedRHSA-2026:3005025.06.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9-operatorFixedRHSA-2026:3005025.06.2026
Red Hat build of Keycloak 26.4.13rhbk/keycloak-rhel9FixedRHSA-2026:3004925.06.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleFixedRHSA-2026:3008425.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1025
https://bugzilla.redhat.com/show_bug.cgi?id=2482472keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

CVSS3: 8.1
debian
около 1 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allow ...

CVSS3: 8.1
github
около 1 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

8.1 High

CVSS3