CVE-2026-9800
Executive Summary
A flaw in Keycloak Policy Enforcer lets any authenticated user bypass all authorization checks—role, scope, and UMA permissions—by embedding the configured access‑denied page path in a request URL (as a path segment or query parameter). This enables attackers to gain unauthorized access to protected resources. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2026-06-25T17:17:04.180 - Last Modified: 2026-09-13T01:16:38.340
Original Description: A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.
"It is the mark of an educated mind to be able to entertain a thought without accepting it."
— Aristotle