CVE-2026-9689Redhat · Build_of_keycloak
Vulnerability data via NVD (ingested)
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-9689product:"Redhat Build Of Keycloak"http.html:"Build Of Keycloak"More intel sources (5)
vuln:CVE-2026-9689vulnerabilities.cve_id: CVE-2026-9689CVE-2026-9689CVE-2026-9689"CVE-2026-9689" exploit -site:nvd.nist.gov