CVE-2026-9792Redhat · Build_of_keycloak
Vulnerability data via NVD (ingested)
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password Credentials (ROPC) grant, even when a policy is explicitly configured to block it. This bypass can lead to unauthorized access and information disclosure.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-9792product:"Redhat Build Of Keycloak"http.html:"Build Of Keycloak"More intel sources (5)
vuln:CVE-2026-9792vulnerabilities.cve_id: CVE-2026-9792CVE-2026-9792CVE-2026-9792"CVE-2026-9792" exploit -site:nvd.nist.gov