PT-2026-97703 · Red Hat · Keycloak

CVE-2026-97176

·

Published

2026-09-24

·

Updated

2026-09-26

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the Level of Authentication enforcement mechanism of Keycloak. The issue arises when a client requires a higher security level for a user who already possesses an active session at a lower level. A logic error during session re-evaluations may cause Keycloak to incorrectly issue a token at the lower security level instead of enforcing the required higher level, which could allow unauthorized access to sensitive resources relying on these security claims.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97176

Affected Products

Keycloak