CVE-2026-9800 Details
Description
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.
An authorization bypass vulnerability has been identified in Keycloak Policy Enforcer versions through 26.0.5. This flaw allows any authenticated user to circumvent all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. The vulnerability arises from an incorrect URI comparison in the 'isDefaultAccessDeniedUri' function, which uses a substring match instead of an exact path comparison. Exploitation involves including the access-denied page path in the request URL, either as a path segment or a query parameter, thereby gaining unauthorized access to protected resources.
Users can upgrade to the Red Hat build of Keycloak 26.6 or 26.6.4, both of which include the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1025 | Comparison Using Wrong Factors | redhat-SADP |
| CWE-1025 | Comparison Using Wrong Factors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.13 >= 26.6, <= 26.6.4 |
CPE
Remediation
| |
Change History
19 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | redhat-SADP |
| Sep 13, 2026 | CVE Modified | redhat-SADP |
| Sep 13, 2026 | CVE Modified | [email protected] |
| Aug 6, 2026 | CVE Modified | redhat-SADP |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Jul 30, 2026 | CVE Modified | redhat-SADP |
| Jul 30, 2026 | CVE Modified | [email protected] |
| Jul 29, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 2, 2026 | CVE Modified | redhat-SADP |
| Jul 2, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |