Junglewise Threat Intelligence

CVE-2026-95503: Keycloak Kerberos KDC spoofing authentication bypass

CVE-2026-95503 · Severity: medium · CVSS 6.8 · Published 2026-09-22

Technologies: Red Hat Keycloak. Vendors: Red Hat.

Executive brief

Keycloak is an open-source identity and access management platform that controls user authentication and authorization. A flaw in its Kerberos authentication provider allows attackers on the same network to impersonate the authentication server and bypass login verification, gaining unauthorized access to user accounts without needing valid credentials.

Technical details

The Kerberos federation provider in Keycloak fails to verify the identity of the Key Distribution Center (KDC) by requesting a server ticket when Kerberos password authentication is used without SPNEGO. This is a cryptographic signature verification flaw (CWE-347) exploitable by adjacent network attackers with no privileges or user interaction required. An attacker can spoof the KDC to intercept and bypass authentication, leading to unauthorized access and data compromise.

Affected products

  • Red Hat Keycloak <unknown

Timeline

  • 2026-09-22: disclosed

References

Related threats