{"id":"CVE-2026-9800","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-9800","summary":"Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison","details":"A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.","published":"2026-08-25T11:42:52.486Z","modified":"2026-08-26T11:15:12.037106537Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Bitnami","name":"keycloak","fixedVersion":"26.4.13"}],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30049"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30050"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30083"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30084"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:50846"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:50847"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-9800"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2482472"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9800"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9800.json"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T11:15:12.037106537Z"}}