Junglewise Threat Intelligence

CVE-2026-9705: Keycloak security bypass in client registration service

CVE-2026-9705 · Severity: medium · CVSS 6.5 · Published 2026-06-25

Technologies: Red Hat build of Keycloak, Keycloak. Vendors: Red Hat, Keycloak.

Executive brief

Keycloak is an open-source identity and access management solution used to secure modern applications and services. A security flaw in its client registration service allows an attacker who has an old registration token to re-activate a client account that an administrator had previously disabled. This could allow the attacker to reset security credentials and gain unauthorized access to protected data or systems.

Technical details

A vulnerability classified as Insufficient Session Expiration (CWE-613) exists in Keycloak's client registration service. A remote attacker possessing a previously issued Registration Access Token (RAT) can bypass administrative security controls to re-enable a client that was explicitly disabled by an administrator. By re-enabling the client, the attacker can reset the client's secret, potentially regaining privileged API access and leading to unauthorized information disclosure or integrity compromise. The attack is reachable over the network and requires the possession of a valid RAT but no other specific privileges.

Affected products

  • Red Hat Red Hat Build of Keycloak
  • Keycloak Keycloak

Timeline

  • 2026-05-27: other: Bug reported to Red Hat Bugzilla
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats