Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-9792

26
FAUCET Score

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password Credentials (ROPC) grant, even when a policy is explicitly configured to block it. This bypass can lead to unauthorized access and information disclosure.

First published: May 28, 2026Last modified: Jun 26, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 9th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.keycloak:keycloak-servicesFixed in: 26.6.3
redhatvendor investigatingvia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Build of KeycloakFixed in: rhbk/keycloak-rhel9

Vendor Advisories (2)

mavenGHSA-33j3-g875-37rpmedium

Keycloak Vulnerable to Improper Handling of Insufficient Permissions or Privilege

May 28, 2026
redhatCVE-2026-9792Moderate

keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition

May 28, 2026

References

access.redhat.com / errata/RHSA-2026:25097
access.redhat.com / errata/RHSA-2026:25098
access.redhat.com / errata/RHSA-2026:30049
access.redhat.com / errata/RHSA-2026:30050
access.redhat.com / security/cve/CVE-2026-9792
MitigationVendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory