Executive brief
Keycloak is an open-source identity and access management solution used to secure modern applications and services. A vulnerability was found where users could bypass security policies when setting up WebAuthn (biometric or hardware key) credentials by manipulating the registration process in their browser. This allows users to register authentication methods that do not meet the organization's security standards, potentially weakening the overall protection of user accounts.
Technical details
A policy bypass vulnerability exists in Keycloak's WebAuthn credential registration flow. The server-side 'processAction()' method in 'keycloak-services' fails to validate that the parameters of a newly created credential (such as public key algorithms, user verification requirements, or resident key settings) align with the realm's configured WebAuthn policies. An authenticated attacker can exploit this by intercepting and modifying the client-side JavaScript or the resulting network request during the registration phase. This allows the registration of credentials using unauthorized or weaker cryptographic algorithms that the administrator intended to prohibit. The issue is addressed in version 26.6.3.
Affected products
- Keycloak keycloak-services <= 26.6.2
Timeline
- 2026-05-18: other: Reported to Red Hat Bugzilla
- 2026-05-19: disclosed: Initial NVD publication
- 2026-05-19: advisory: GitHub Advisory published
- 2026-05-29: patched: Fix merged into main branch
- 2026-06-04: other: GitHub Advisory reviewed and updated