{"id":"CVE-2026-96445","title":"A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution","summary":"A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, …","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-287"],"vendor":"Red Hat","product":"keycloak-services","affected":["keycloak-services (all versions)","rhbk/keycloak-rhel9 (all versions)","keycloak-services"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T20:17:25.677","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96445","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-96445","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539280","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-23T18:18:59.386636Z"},"ingestedAt":"2026-09-23T11:22:32.917Z","slug":"CVE-2026-96445","body":"## Overview\n\nA flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}