CVE-2026-9705
Last modified
CVE-2026-9705 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | >= 26.4, < 26.4.13 |
| Redhat | Build Of Keycloak | >= 26.6, < 26.6.4 |
References
- https://access.redhat.com/errata/RHSA-2026:30049Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:30050Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:30083Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:30084Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-9705Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2481878Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9705?
How severe is CVE-2026-9705?
How do I fix CVE-2026-9705?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9698DBI versions before 1.648 for Perl saved errors in a limited…9.8
- CVE-2026-9699Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 …6.8
- CVE-2026-9700The Eventer plugin for WordPress is vulnerable to time-based…7.5
- CVE-2026-9701The Eventer plugin for WordPress is vulnerable to an insecur…9.8
- CVE-2026-9702The InPost PL WordPress plugin before 1.9.1 does not verify …7.5
- CVE-2026-9704A flaw was found in Keycloak. An authenticated user with low…8.8
- CVE-2026-97055SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenize…8.1
- CVE-2026-97056SigNoz versions from v0.98.0 up to (but not including) v0.14…6.8
- CVE-2026-97057redis-parser through 3.0.0 fails to validate the multi-bulk …7.5
- CVE-2026-97058sprintf-js through 1.1.3 passes unbounded precision specifie…5.3
- CVE-2026-97059DCMTK through 3.7.0 contains a heap over-read vulnerability …8.2
- CVE-2026-97060X-SpringBoot through 6.0 lacks object-level authorization in…7.2
Are you affected by CVE-2026-9705?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
