PT-2026-43993 · Red Hat · Keycloak

Filip Jovanov

+1

·

Published

2026-05-27

·

Updated

2026-06-10

·

CVE-2026-9704

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description An authenticated user with low privileges can achieve privilege escalation by sending an oversized JSON Web Token (JWT), which is a compact, URL-safe means of representing claims to be transferred between two parties, to the 'TokenEndpoint'. When the subject token exceeds 4000 characters, the system silently drops it and falls back to client credentials, granting the user the permissions of the client's service account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9704

Affected Products

Keycloak