---
id: CVE-2026-18209
title: >-
  A flaw was found in the keycloak-services component of Keycloak, which handles
  OpenID Connect (OIDC) authentication flows
summary: >-
  A flaw was found in the keycloak-services component of Keycloak, which handles
  OpenID Connect (OIDC) authentication flows. The issue occurs because the
  security check designed to prevent HTTP parameter pollution only inspects the
  query p…
severity: low
cvss: 3.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N'
cwe:
  - CWE-1288
vendor: redhat
product: build_of_keycloak
affected:
  - build_of_keycloak
patched:
  - build_of_keycloak 26.6.7
published: '2026-07-31'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:17:08.720'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18209'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:68277'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68278'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18209'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2508305'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18209.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18209'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18209'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00409
epssPercentile: 0.32291
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-31T15:56:41.018515Z'
ingestedAt: '2026-08-08T14:22:57.429Z'
---

## Overview

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.

## Affected

- `build_of_keycloak`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)
- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)
