CVE-2026-9792: Improper Handling of Insufficient Permissions or Privileges in Red Hat Red Hat Build of Keycloak
CVE-2026-9792 is a vulnerability in Red Hat Build of Keycloak affecting the Client Policies component. Specifically, when certain condition providers are used to enforce security restrictions, the 'reject-ropc-grant' executor can be bypassed silently. This allows an unauthenticated remote attacker to obtain tokens via the Resource Owner Password Credentials (ROPC) grant despite explicit policies blocking it. The vulnerability can lead to unauthorized access and information disclosure. The CVSS score is 6. 5 (medium severity). There is no confirmed patch or official remediation available as per the vendor advisory at this time.
AI Analysis
Technical Summary
This vulnerability exists in the 'org.keycloak.protocol.oidc' component of Red Hat Build of Keycloak's Client Policies. When condition providers such as client-type, client-roles, client-attributes, or client-scopes are used, the 'reject-ropc-grant' executor designed to block ROPC grants can be bypassed silently. This bypass enables an unauthenticated remote attacker to obtain tokens via the ROPC grant flow even when policies explicitly forbid it. The issue results from improper handling of insufficient permissions or privileges in the enforcement logic of client policies. The vulnerability is publicly documented with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N, indicating network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and low confidentiality and integrity impact without availability impact. No known exploits in the wild have been reported. The vendor advisory does not currently confirm a patch or remediation.
Potential Impact
An unauthenticated remote attacker can bypass configured client policies that are intended to block the Resource Owner Password Credentials grant type. This allows the attacker to obtain authentication tokens without proper authorization, potentially leading to unauthorized access to protected resources and information disclosure. The impact is limited to confidentiality and integrity with no reported availability impact. The medium CVSS score reflects the moderate risk posed by this vulnerability.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-9792 for current remediation guidance. Until an official fix is released, administrators should review and potentially disable the use of the ROPC grant type or avoid using the affected condition providers in client policies as a temporary mitigation. Monitor Red Hat's advisory for updates on patches or official workarounds.
CVE-2026-9792: Improper Handling of Insufficient Permissions or Privileges in Red Hat Red Hat Build of Keycloak
Description
CVE-2026-9792 is a vulnerability in Red Hat Build of Keycloak affecting the Client Policies component. Specifically, when certain condition providers are used to enforce security restrictions, the 'reject-ropc-grant' executor can be bypassed silently. This allows an unauthenticated remote attacker to obtain tokens via the Resource Owner Password Credentials (ROPC) grant despite explicit policies blocking it. The vulnerability can lead to unauthorized access and information disclosure. The CVSS score is 6. 5 (medium severity). There is no confirmed patch or official remediation available as per the vendor advisory at this time.
CVSS v3.1
Score 6.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the 'org.keycloak.protocol.oidc' component of Red Hat Build of Keycloak's Client Policies. When condition providers such as client-type, client-roles, client-attributes, or client-scopes are used, the 'reject-ropc-grant' executor designed to block ROPC grants can be bypassed silently. This bypass enables an unauthenticated remote attacker to obtain tokens via the ROPC grant flow even when policies explicitly forbid it. The issue results from improper handling of insufficient permissions or privileges in the enforcement logic of client policies. The vulnerability is publicly documented with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N, indicating network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and low confidentiality and integrity impact without availability impact. No known exploits in the wild have been reported. The vendor advisory does not currently confirm a patch or remediation.
Potential Impact
An unauthenticated remote attacker can bypass configured client policies that are intended to block the Resource Owner Password Credentials grant type. This allows the attacker to obtain authentication tokens without proper authorization, potentially leading to unauthorized access to protected resources and information disclosure. The impact is limited to confidentiality and integrity with no reported availability impact. The medium CVSS score reflects the moderate risk posed by this vulnerability.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-9792 for current remediation guidance. Until an official fix is released, administrators should review and potentially disable the use of the ROPC grant type or avoid using the affected condition providers in client policies as a temporary mitigation. Monitor Red Hat's advisory for updates on patches or official workarounds.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-05-28T03:09:25.012Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-9792","vendor":"Red Hat"}]
Threat ID: 6a189d28e29bf47b50227aff
Added to database: 5/28/2026, 7:53:12 PM
Last enriched: 5/28/2026, 8:04:09 PM
Last updated: 5/28/2026, 9:00:48 PM
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.