Количество 4
Количество 4
CVE-2026-9798
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.
CVE-2026-9798
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.
CVE-2026-9798
A flaw was found in Keycloak, an open-source identity and access manag ...
GHSA-q6h7-xxp7-7429
Keycloak has an Authentication Bypass by Primary Weakness
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9798 A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-9798 A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-9798 A flaw was found in Keycloak, an open-source identity and access manag ... | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
GHSA-q6h7-xxp7-7429 Keycloak has an Authentication Bypass by Primary Weakness | CVSS3: 4.3 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу