CVE-2026-9792 Details
Description
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password Credentials (ROPC) grant, even when a policy is explicitly configured to block it. This bypass can lead to unauthorized access and information disclosure.
A vulnerability exists in Keycloak's Client Policies within the 'org.keycloak.protocol.oidc' component. This flaw allows an unauthenticated remote attacker to bypass security restrictions enforced by certain condition providers (client-type, client-roles, client-attributes, client-scopes). When these providers are used, the 'reject-ropc-grant' executor is silently ignored, enabling the attacker to obtain tokens through a Resource Owner Password Credentials (ROPC) grant, despite explicit policy configurations to block such actions. This bypass could lead to unauthorized access and information disclosure.
Keycloak administrators should review and adjust client policies that reject ROPC grants. It is recommended to avoid using the 'client-type', 'client-roles', 'client-attributes', or 'client-scopes' condition providers with the 'reject-ropc-grant' executor. Instead, policies should be configured to use the 'grant-type' condition provider for rejecting ROPC grants. A restart or reload of the Keycloak service may be necessary for these changes to take effect.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-280 | Improper Handling of Insufficient Permissions or Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | All versions |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | [email protected] |