CVE-2026-74909
Last modified
CVE-2026-74909 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments.
Description
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | All versions |
| Red Hat | Red Hat build of Keycloak 26.6 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-74909?
How severe is CVE-2026-74909?
How do I fix CVE-2026-74909?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74903SiYuan before v3.7.4 contains an insufficient access control…4.3
- CVE-2026-74904SiYuan before v3.7.4 is missing authorization checks in 17 b…7.5
- CVE-2026-74905SiYuan before v3.7.4 contains a server-side request forgery …7.1
- CVE-2026-74906SiYuan before v3.7.4 contains an incorrect authorization vul…7.5
- CVE-2026-74907Grav before 2.0.15 contains a path traversal vulnerability i…5.9
- CVE-2026-74908Grav plugin-api before 1.0.15 contains a script injection vu…4.6
- CVE-2026-7491School App developed by Zyosoft has an Insecure Direct Objec…8.6
- CVE-2026-74916The WP Fastest Cache WordPress plugin before 1.5.1 does not …6.5
- CVE-2026-7492GitLab has remediated an issue in GitLab CE/EE affecting all…5.3
- CVE-2026-74925The MultiVendorX WordPress plugin before 5.0.16 does not re…7.2
- CVE-2026-74926The MultiVendorX WordPress plugin before 5.0.16 does not ve…7.1
- CVE-2026-74927The MultiVendorX WordPress plugin before 5.0.15 does not ha…5.3
Are you affected by CVE-2026-74909?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
