PT-2026-52510 · Red Hat · Keycloak Policy Enforcer+1

·

CVE-2026-9800

·

Published

2026-06-25

·

Updated

2026-08-25

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak Policy Enforcer (affected versions not specified)
Description An issue exists that allows authenticated users to bypass authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. An attacker can gain unauthorized access to protected resources by including the configured access-denied page path within a request URL, either as a path segment or a query parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-9800
CVE-2026-9800

Affected Products

Keycloak
Keycloak Policy Enforcer