---
id: CVE-2026-74909
title: >-
  Keycloak provides a policy enforcer to protect applications by matching
  incoming web requests against defined security policies
summary: >-
  Keycloak provides a policy enforcer to protect applications by matching
  incoming web requests against defined security policies. A flaw was found
  where the enforcer fails to correctly normalize web addresses that contain
  special encoded …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: Red Hat
product: rhbk/keycloak-operator-bundle
affected:
  - rhbk/keycloak-operator-bundle (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - keycloak/rhbk-openshift-rhel9
  - keycloak-services
  - rhbk/keycloak-operator-bundle (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - keycloak/rhbk-openshift-rhel9
  - keycloak-services
  - keycloak-services
patched:
  - build_of_keycloak 26.4
  - build_of_keycloak 26.4.16
  - build_of_keycloak 26.6.7
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:12.197'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74909'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:68276'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68277'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68278'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68280'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-74909'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2517354'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-74909.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-74909'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74909'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T18:03:50.855409Z'
epss: 0.00847
epssPercentile: 0.56308
ingestedAt: '2026-09-16T14:57:28.028Z'
---

## Overview

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:68276** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68276)
- **RHSA-2026:68280** · Red Hat · fixed in: Red Hat build of Keycloak 26.4.16 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68280)
- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)
- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)
