Junglewise Threat Intelligence

CVE-2026-9793: Keycloak signature policy bypass in JWE-encrypted request objects

CVE-2026-9793 · Severity: medium · CVSS 5.9 · Published 2026-05-28

Technologies: Red Hat build of Keycloak, org.keycloak:keycloak-services (Maven), Red Hat build of Keycloak, Keycloak. Vendors: Red Hat, Maven, Keycloak.

Executive brief

Keycloak, an open-source identity and access management solution, contains a flaw in how it handles encrypted login requests. An attacker could bypass security policies to submit unauthorized data during the login process, potentially compromising the integrity of user authentication. While existing security controls like redirect allowlists provide some protection, this issue allows for the submission of unsigned data that should otherwise be rejected.

Technical details

An improper verification of cryptographic signatures (CWE-347) exists in Keycloak's OIDC request object processing. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may decrypt the content and process it as raw JSON without enforcing the configured 'requestObjectSignatureAlg' policy. This allows an attacker to bypass mandatory signing requirements (such as RS256) by wrapping unsigned claims in a JWE envelope. The vulnerability violates OIDC Core and FAPI requirements, though impact is partially mitigated by redirect URI allowlists. As of the advisory, no patch is explicitly confirmed for version 26.6.4.

Affected products

  • Keycloak Keycloak <= 26.6.4
  • Red Hat Red Hat Build of Keycloak -

Timeline

  • 2026-05-28: disclosed: Vulnerability reported and GHSA published
  • 2026-05-28: advisory: NVD and Red Hat advisories published

References

Related threats