A AegiFlow
MEDIUMCVSS 4.2EPSS 0.3%

CVE-2026-9689

CVE-2026-9689 updated by NVD

Published
2026-05-27
Modified
2026-08-21
EPSS percentile
25%
Sources
github-advisory, nvd

Summary

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.keycloak:keycloak-services

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.