Junglewise Threat Intelligence

CVE-2026-9086: Keycloak XSS via case-insensitive URI validation bypass

CVE-2026-9086 · Severity: high · CVSS 7.3 · Published 2026-06-25

Technologies: Red Hat build of Keycloak, Red Hat Keycloak. Vendors: Red Hat.

Executive brief

Keycloak, an open-source identity and access management solution, is vulnerable to a security flaw that allows administrative users to bypass safety checks. By creating malicious links, an attacker can execute unauthorized code in the browser of other users, including other administrators. This could lead to the theft of sensitive session information or unauthorized actions being performed within the management console.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Keycloak due to improper neutralization of input during client URI validation (CWE-79). An attacker with 'manage-client' permissions or access to client registration endpoints can bypass validation by using case-insensitive 'javascript:' or 'data:' schemes in redirect URIs. When a victim interacts with these crafted URIs—for instance, during a logout flow or within the Admin Console—arbitrary JavaScript executes in the Keycloak origin. This allows for session hijacking or unauthorized administrative actions. The vulnerability is tracked as CVE-2026-9086.

Affected products

  • Red Hat Keycloak unspecified
  • Red Hat Red Hat Build of Keycloak unspecified

Timeline

  • 2026-05-20: other: Reported to Red Hat Bugzilla
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats