CVE-2026-9798: Keycloak has an Authentication Bypass by Primary Weakness
(updated )
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.
References
- access.redhat.com/security/cve/CVE-2026-9798
- bugzilla.redhat.com/show_bug.cgi?id=2482470
- github.com/advisories/GHSA-q6h7-xxp7-7429
- github.com/keycloak/keycloak/commit/11c2695064cd93da1d333df3f69d4a4141e86c29
- github.com/keycloak/keycloak/commit/2edc6b112e2dedce63062b89ab3c7ae542e0d9ac
- github.com/keycloak/keycloak/commit/a11e3254efc16ae72ce5092b93b9f557a4ba43ae
- github.com/keycloak/keycloak/issues/49432
- github.com/keycloak/keycloak/pull/49791
- github.com/keycloak/keycloak/pull/49903
- github.com/keycloak/keycloak/pull/49905
- nvd.nist.gov/vuln/detail/CVE-2026-9798
Code Behaviors & Features
Detect and mitigate CVE-2026-9798 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →