{"id":"CVE-2026-74909","title":"Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies","summary":"Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-862"],"vendor":"Red Hat","product":"rhbk/keycloak-operator-bundle","affected":["rhbk/keycloak-operator-bundle (all versions)","rhbk/keycloak-rhel9 (all versions)","rhbk/keycloak-rhel9-operator (all versions)","keycloak/rhbk-openshift-rhel9","keycloak-services","rhbk/keycloak-operator-bundle (all versions)","rhbk/keycloak-rhel9 (all versions)","rhbk/keycloak-rhel9-operator (all versions)","keycloak/rhbk-openshift-rhel9","keycloak-services","keycloak-services"],"patched":["build_of_keycloak 26.4","build_of_keycloak 26.4.16","build_of_keycloak 26.6.7"],"published":"2026-09-16","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:12.197","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74909","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:68276","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68277","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68278","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68280","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-74909","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517354","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-74909.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74909"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74909"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T18:03:50.855409Z"},"epss":0.00893,"epssPercentile":0.57425,"ingestedAt":"2026-09-16T14:57:28.028Z","slug":"CVE-2026-74909","body":"## Overview\n\nKeycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:68276** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68276)\n- **RHSA-2026:68280** · Red Hat · fixed in: Red Hat build of Keycloak 26.4.16 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68280)\n- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)\n- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}