Red Hat build of Keycloak 26.4 vulnerability

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

Published 25 Jun 2026Updated 12 Sep 202619 sources
CVSS 8.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.