CVE-2026-9794: Keycloak Generates an Error Message Containing Sensitive Information
(updated )
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client’s protocol type, leading to information disclosure.
References
- access.redhat.com/errata/RHSA-2026:25097
- access.redhat.com/errata/RHSA-2026:25098
- access.redhat.com/errata/RHSA-2026:30049
- access.redhat.com/errata/RHSA-2026:30050
- access.redhat.com/security/cve/CVE-2026-9794
- bugzilla.redhat.com/show_bug.cgi?id=2482461
- github.com/advisories/GHSA-fqjh-8322-vgrv
- github.com/keycloak/keycloak/commit/05e98366773eec60878bb2a6d5da6bc7048ac3c8
- github.com/keycloak/keycloak/commit/7750e3ff823d1da8580d42c51194feb2e933b87b
- github.com/keycloak/keycloak/commit/dba79eb03fb9d634fda5e86e1613b8747f968518
- github.com/keycloak/keycloak/issues/49428
- github.com/keycloak/keycloak/pull/49684
- github.com/keycloak/keycloak/pull/49686
- nvd.nist.gov/vuln/detail/CVE-2026-9794
Code Behaviors & Features
Detect and mitigate CVE-2026-9794 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →