CVE-2026-9704: Improper Validation of Specified Quantity in Input in Red Hat Red Hat build of Keycloak 26.4
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This allows the user to gain the permissions of the client's service account, leading to privilege escalation.
AI Analysis
Technical Summary
An authenticated user with low privileges in Red Hat build of Keycloak 26.4 can exploit improper validation of the subject_token JWT by sending an oversized token (>4000 characters) to the TokenEndpoint. The system drops the oversized token silently and falls back to client credentials, granting the user the permissions of the client's service account, resulting in privilege escalation. The vulnerability is tracked as CVE-2026-9704 with a CVSS 3.1 score of 6.8 (medium). Red Hat has published security advisories and released new Keycloak 26.6.3 images that include fixes for this issue. No direct patch for version 26.4 is mentioned, but upgrading to 26.6.3 is the recommended remediation.
Potential Impact
Successful exploitation allows a low-privileged authenticated user to escalate privileges by acquiring the permissions of the client's service account due to fallback on client credentials when an oversized JWT is submitted. This can lead to unauthorized access and elevated permissions within the Keycloak authentication system. There is no reported impact on availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released updated Keycloak 26.6.3 images that address this vulnerability. Users should upgrade to Red Hat build of Keycloak 26.6.3 or later to remediate this issue. Before applying the update, back up existing installations, including applications, configuration files, and databases. Patch status for version 26.4 is not explicitly stated; therefore, check the Red Hat advisory for the latest remediation guidance. No other specific mitigations are provided.
CVE-2026-9704: Improper Validation of Specified Quantity in Input in Red Hat Red Hat build of Keycloak 26.4
Description
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This allows the user to gain the permissions of the client's service account, leading to privilege escalation.
CVSS v3.1
Score 6.8medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An authenticated user with low privileges in Red Hat build of Keycloak 26.4 can exploit improper validation of the subject_token JWT by sending an oversized token (>4000 characters) to the TokenEndpoint. The system drops the oversized token silently and falls back to client credentials, granting the user the permissions of the client's service account, resulting in privilege escalation. The vulnerability is tracked as CVE-2026-9704 with a CVSS 3.1 score of 6.8 (medium). Red Hat has published security advisories and released new Keycloak 26.6.3 images that include fixes for this issue. No direct patch for version 26.4 is mentioned, but upgrading to 26.6.3 is the recommended remediation.
Potential Impact
Successful exploitation allows a low-privileged authenticated user to escalate privileges by acquiring the permissions of the client's service account due to fallback on client credentials when an oversized JWT is submitted. This can lead to unauthorized access and elevated permissions within the Keycloak authentication system. There is no reported impact on availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released updated Keycloak 26.6.3 images that address this vulnerability. Users should upgrade to Red Hat build of Keycloak 26.6.3 or later to remediate this issue. Before applying the update, back up existing installations, including applications, configuration files, and databases. Patch status for version 26.4 is not explicitly stated; therefore, check the Red Hat advisory for the latest remediation guidance. No other specific mitigations are provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-05-27T12:39:12.284Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-9704","vendor":"Red Hat"}]
Threat ID: 6a16f9eae29bf47b50c0f5c1
Added to database: 05/27/2026, 14:04:26 UTC
Last enriched: 06/26/2026, 12:22:19 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.