A AegiFlow
MEDIUMCVSS 4.3EPSS 0.3%

CVE-2026-9798

CVE-2026-9798 updated by NVD

Published
2026-05-28
Modified
2026-08-21
EPSS percentile
27%
Sources
github-advisory, nvd

Summary

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.keycloak:keycloak-services

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.