« Volver al listado

CVE-2026-9689

Estado: ModificadaMedia (4.2)—

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-9689",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-9689",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-27T14:45:36.377913Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.2,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4.14-1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4-22",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.4-22",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.4.14",
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.6",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.6.5-1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.6",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.6-11",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.6",
          "versions": [
            {
              "status": "unaffected",
              "version": "26.6-11",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:26.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 26.6.5",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-27T12:17:15.513",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:50846",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:50847",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:50848",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:50849",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-9689",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481845",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1288"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources."
    }
  ],
  "lastModified": "2026-08-20T01:16:54.447",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5C930CB-4EAD-497B-A44B-D880F2A1F85B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}