Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.keycloak/keycloak-services
  4. ›
  5. CVE-2026-9802

CVE-2026-9802: Keycloak has Insufficient Session Expiration

May 28, 2026 (updated July 1, 2026)

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user’s refresh token, to replay that token even after it has been revoked. Successful exploitation grants the attacker unauthorized access to the victim’s account, potentially leading to information disclosure or privilege escalation.

References

  • access.redhat.com/errata/RHSA-2026:25097
  • access.redhat.com/errata/RHSA-2026:25098
  • access.redhat.com/errata/RHSA-2026:30049
  • access.redhat.com/errata/RHSA-2026:30050
  • access.redhat.com/security/cve/CVE-2026-9802
  • bugzilla.redhat.com/show_bug.cgi?id=2482467
  • github.com/advisories/GHSA-v5g5-wwmp-jppw
  • github.com/keycloak/keycloak/commit/165df48d3f0f42ede8e6082184892ca7cc703989
  • github.com/keycloak/keycloak/commit/3451217e3837ce5e8bbcac2773f0ac44830b95f1
  • github.com/keycloak/keycloak/commit/3fde018b98e2729a594a3ac7fc730fde31da2f07
  • github.com/keycloak/keycloak/issues/49426
  • github.com/keycloak/keycloak/pull/49542
  • github.com/keycloak/keycloak/pull/49619
  • github.com/keycloak/keycloak/pull/49620
  • nvd.nist.gov/vuln/detail/CVE-2026-9802

Code Behaviors & Features

Detect and mitigate CVE-2026-9802 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 26.4.7, all versions starting from 26.5.0 before 26.6.3

Fixed versions

  • 26.6.3

Solution

Upgrade to version 26.6.3 or above.

Impact 6.8 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-613: Insufficient Session Expiration

Source file

maven/org.keycloak/keycloak-services/CVE-2026-9802.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 00:16:54 +0000.