Red Hat build of Keycloak 26.6 vulnerability

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.

Published 17 Jul 2026Updated 16 Sep 20264 sources
CVSS 5.4

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.