CVE-2026-96446Medium· 4.2▾ SunlitA flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is alre…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request URI is used only once is not enforced. An attacker could potentially reuse a request URI to obtain multiple authorization codes for a user who is already signed in, violating security standards like FAPI-2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96445Medium· 6.8A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution
CVE-2026-94218Low· 3.1A flaw was found in the authentication session management of Keycloak, an identity and access management solution
CVE-2026-94217Low· 3.5A flaw was found in the User-Managed Access (UMA) implementation of Keycloak
CVE-2026-94213Medium· 4.9A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution
CVE-2026-94215Medium· 5.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution
CVE-2025-1391Medium· 5.4A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern